Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3445
HistoryFeb 06, 2017 - 2:21 a.m.

Protection Mechanism Bypass

2017-02-0602:21:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
29

EPSS

0.123

Percentile

95.5%

OpenSSL is vulnerable to protection mechanism bypass. This is because OpenSSL accepts several variations of certificate signature algorithms and signature encodings. It doesn’t then enforce a match between the signature algorithm between the signed and unsigned portions of the certificate. This only affects custom applications which rely on the uniqueness of the fingerprint.

References