CVE-2009-0653Improper Authentication in Openssl

Severity
7.5HIGHNVD
EPSS
0.3%
top 50.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 20
Latest updateMay 2

Description

OpenSSL, probably 0.9.6, does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack, a related issue to CVE-2002-0970.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/openssl< openssl 0.9.8-1 (bookworm)
Debianopenssl/openssl< 0.9.8-1+3
NVDopenssl/openssl0.9.6

🔴Vulnerability Details

2
GHSA
GHSA-gj63-3383-h48m: OpenSSL, probably 02022-05-02
OSV
CVE-2009-0653: OpenSSL, probably 02009-02-20

📋Vendor Advisories

2
Debian
CVE-2009-0653: openssl - OpenSSL, probably 0.9.6, does not verify the Basic Constraints for an intermedia...2009
Red Hat
CVE-2009-0653: OpenSSL, probably 0