10 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:C/I:C/A:C
6.2 Medium
AI Score
Confidence
Low
0.933 High
EPSS
Percentile
99.1%
The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication.
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt
marc.info/?l=bugtraq&m=108726102304507&w=2
marc.info/?l=bugtraq&m=108731967126033&w=2
secunia.com/advisories/11863
secunia.com/advisories/11877
security.gentoo.org/glsa/glsa-200406-17.xml
securitytracker.com/id?1010495
sourceforge.net/project/shownotes.php?release_id=245982
www.osvdb.org/7113
www.redhat.com/support/errata/RHSA-2004-308.html
www.securityfocus.com/bid/10546
exchange.xforce.ibmcloud.com/vulnerabilities/16414
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9163