*** This bug is a security vulnerability ***

Public security bug reported:

Binary package hint: stunnel4

CVE-2008-2420 description:

"The OCSP functionality in stunnel before 4.24 does not properly search
certificate revocation lists (CRL), which allows remote attackers to
bypass intended access restrictions by using revoked certificates. "

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2420

The bug has been already fixed in Intrepid. This is a request to
backport the fix to Hardy.

** Affects: stunnel4 (Ubuntu)
     Importance: Undecided
         Status: New

** Visibility changed to: Public

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2008-2420

-- 
[CVE-2008-2420] stunnel incorrect OCSP validation vulnerability
https://bugs.launchpad.net/bugs/257949
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to