Lucene search

K
cveMitreCVE-2009-0642
HistoryFeb 20, 2009 - 6:47 a.m.

CVE-2009-0642

2009-02-2006:47:48
CWE-287
mitre
web.nvd.nist.gov
41
security
vulnerability
ruby
remote attackers
x.509 certificate

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.021

Percentile

89.3%

ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.

Affected configurations

Nvd
Node
ruby-langrubyMatch1.8
OR
ruby-langrubyMatch1.9
VendorProductVersionCPE
ruby-langruby1.8cpe:2.3:a:ruby-lang:ruby:1.8:*:*:*:*:*:*:*
ruby-langruby1.9cpe:2.3:a:ruby-lang:ruby:1.9:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.021

Percentile

89.3%