CVE-2011-3207
published 2011-09-22CVE-2011-3207: crypto/x509/x509_vfy.c in OpenSSL 1.0.x before 1.0.0e does not initialize certain structure members, which makes it easier for remote attackers to bypass CRL…
PriorityP432medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
5.01%
91.3th percentile
crypto/x509/x509_vfy.c in OpenSSL 1.0.x before 1.0.0e does not initialize certain structure members, which makes it easier for remote attackers to bypass CRL validation by using a nextUpdate value corresponding to a time in the past.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 1.0.0e-1 (bookworm) | openssl 1.0.0e-1 (bookworm) |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | >= 0 < 1.0.0e-1 | 1.0.0e-1 |
| openssl | openssl | >= 0 < 1.0.0e-1 | 1.0.0e-1 |
| openssl | openssl | >= 0 < 1.0.0e-1 | 1.0.0e-1 |
| openssl | openssl | >= 0 < 1.0.0e-1 | 1.0.0e-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-crcf-r7r4-xr8j: crypto/x509/x509_vfy
ghsa_unreviewed·2022-05-17
CVE-2011-3207 [MEDIUM] GHSA-crcf-r7r4-xr8j: crypto/x509/x509_vfy
crypto/x509/x509_vfy.c in OpenSSL 1.0.x before 1.0.0e does not initialize certain structure members, which makes it easier for remote attackers to bypass CRL validation by using a nextUpdate value corresponding to a time in the past.
OSV
CVE-2011-3207: crypto/x509/x509_vfy
osv·2011-09-22·CVSS 5.0
CVE-2011-3207 [MEDIUM] CVE-2011-3207: crypto/x509/x509_vfy
crypto/x509/x509_vfy.c in OpenSSL 1.0.x before 1.0.0e does not initialize certain structure members, which makes it easier for remote attackers to bypass CRL validation by using a nextUpdate value corresponding to a time in the past.
Red Hat
openssl: CRL verification vulnerability
vendor_redhat·2011-09-06·CVSS 5.0
CVE-2011-3207 [MEDIUM] openssl: CRL verification vulnerability
openssl: CRL verification vulnerability
crypto/x509/x509_vfy.c in OpenSSL 1.0.x before 1.0.0e does not initialize certain structure members, which makes it easier for remote attackers to bypass CRL validation by using a nextUpdate value corresponding to a time in the past.
Statement: This issue did not affect the versions of openssl as shipped with Red Hat Enterprise Linux 4 and 5, openssl096b as shipped with Red Hat Enterprise Linux 4, openssl097a as shipped with Red Hat Enterprise Linux 5, or openssl098e as shipped with Red Hat Enterprise Linux 6.
Package: openssl (Red Hat Enterprise Linux 4) - Not affected
Package: openssl096b (Red Hat Enterprise Linux 4) - Not affected
Package: openssl (Red Hat Enterprise Linux 5) - Not affected
Package: openssl097a (Red Hat Enterprise Linux 5) -
Debian
CVE-2011-3207: openssl - crypto/x509/x509_vfy.c in OpenSSL 1.0.x before 1.0.0e does not initialize certai...
vendor_debian·2011·CVSS 5.0
CVE-2011-3207 [MEDIUM] CVE-2011-3207: openssl - crypto/x509/x509_vfy.c in OpenSSL 1.0.x before 1.0.0e does not initialize certai...
crypto/x509/x509_vfy.c in OpenSSL 1.0.x before 1.0.0e does not initialize certain structure members, which makes it easier for remote attackers to bypass CRL validation by using a nextUpdate value corresponding to a time in the past.
Scope: local
bookworm: resolved (fixed in 1.0.0e-1)
bullseye: resolved (fixed in 1.0.0e-1)
forky: resolved (fixed in 1.0.0e-1)
sid: resolved (fixed in 1.0.0e-1)
trixie: resolved (fixed in 1.0.0e-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3207 mingw-openssl: CRL verification vulnerability [fedora-all]
bugzilla·2012-08-07·CVSS 5.0
CVE-2011-3207 [MEDIUM] CVE-2011-3207 mingw-openssl: CRL verification vulnerability [fedora-all]
CVE-2011-3207 mingw-openssl: CRL verification vulnerability [fedora-all]
+++ This bug was initially created as a clone of Bug #736089 +++
Package renamed in F17+, but does not seem fixed.
Discussion:
mingw-openssl-1.0.1c-1.fc18 has been submitted as an update for Fedora 18.
https://admin.fedoraproject.org/updates/mingw-openssl-1.0.1c-1.fc18
---
Package mingw-openssl-1.0.1c-1.fc18:
* should fix your issue,
* was pushed to the Fedora 18 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing mingw-openssl-1.0.1c-1.fc18'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2012-18035/mingw-openssl-1.0.1c-1.fc18
then log in and leave karma (feedb
Bugzilla
CVE-2011-3207 mingw32-openssl: CRL verification vulnerability [fedora-all]
bugzilla·2011-09-06·CVSS 5.0
CVE-2011-3207 [MEDIUM] CVE-2011-3207 mingw32-openssl: CRL verification vulnerability [fedora-all]
CVE-2011-3207 mingw32-openssl: CRL verification vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=736087
Please note: this issue affects multiple
Bugzilla
CVE-2011-3207 openssl: CRL verification vulnerability
bugzilla·2011-09-06·CVSS 5.0
CVE-2011-3207 [MEDIUM] CVE-2011-3207 openssl: CRL verification vulnerability
CVE-2011-3207 openssl: CRL verification vulnerability
From the upstream advisory [1]:
Under certain circumstances OpenSSL's internal certificate verification
routines can incorrectly accept a CRL whose nextUpdate field is in the past.
(CVE-2011-3207)
This issue applies to OpenSSL versions 1.0.0 through 1.0.0d. Versions of
OpenSSL before 1.0.0 are not affected.
Users of affected versions of OpenSSL should update to the OpenSSL 1.0.0e
release, which contains a patch to correct this issue.
Thanks to Kaspar Brand for identifying this bug and
suggesting a fix.
Applications are only affected by the CRL checking vulnerability if they enable
OpenSSL's internal CRL checking which is off by default. For example by setting
the verification flag X509_V_FLAG_CRL_CHECK or X509_V_FLAG_CRL_CHECK_ALL
Bugzilla
CVE-2011-3207 openssl: CRL verification vulnerability [fedora-all]
bugzilla·2011-09-06·CVSS 5.0
CVE-2011-3207 [MEDIUM] CVE-2011-3207 openssl: CRL verification vulnerability [fedora-all]
CVE-2011-3207 openssl: CRL verification vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=736087
Please note: this issue affects multiple support
http://cvs.openssl.org/chngview?cn=21349http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-September/065712.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-September/065744.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-November/092905.htmlhttp://marc.info/?l=bugtraq&m=133226187115472&w=2http://openssl.org/news/secadv_20110906.txthttp://secunia.com/advisories/45956http://secunia.com/advisories/57353http://support.apple.com/kb/HT5784http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564http://www.mandriva.com/security/advisories?name=MDVSA-2011:137http://www.redhat.com/support/errata/RHSA-2011-1409.htmlhttp://www.securitytracker.com/id?1026012https://bugzilla.redhat.com/show_bug.cgi?id=736087http://cvs.openssl.org/chngview?cn=21349http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-September/065712.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-September/065744.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-November/092905.htmlhttp://marc.info/?l=bugtraq&m=133226187115472&w=2http://openssl.org/news/secadv_20110906.txthttp://secunia.com/advisories/45956http://secunia.com/advisories/57353http://support.apple.com/kb/HT5784http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564http://www.mandriva.com/security/advisories?name=MDVSA-2011:137http://www.redhat.com/support/errata/RHSA-2011-1409.htmlhttp://www.securitytracker.com/id?1026012https://bugzilla.redhat.com/show_bug.cgi?id=736087
2011-09-22
Published