Lucene search

K
nvd[email protected]NVD:CVE-2009-0642
HistoryFeb 20, 2009 - 6:47 a.m.

CVE-2009-0642

2009-02-2006:47:48
CWE-287
web.nvd.nist.gov
5

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.021

Percentile

89.3%

ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.

Affected configurations

Nvd
Node
ruby-langrubyMatch1.8
OR
ruby-langrubyMatch1.9
VendorProductVersionCPE
ruby-langruby1.8cpe:2.3:a:ruby-lang:ruby:1.8:*:*:*:*:*:*:*
ruby-langruby1.9cpe:2.3:a:ruby-lang:ruby:1.9:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.021

Percentile

89.3%