OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificates unsigned portion, related to crypto/asn1/a_verify.c, crypto/dsa/dsa_asn1.c, crypto/ecdsa/ecs_vrf.c, and crypto/x509/x_all.c.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openssl | Openssl | * | 0.9.8zc (including) |
Openssl | Openssl | 1.0.0a (including) | 1.0.0a (including) |
Openssl | Openssl | 1.0.0b (including) | 1.0.0b (including) |
Openssl | Openssl | 1.0.0c (including) | 1.0.0c (including) |
Openssl | Openssl | 1.0.0d (including) | 1.0.0d (including) |
Openssl | Openssl | 1.0.0e (including) | 1.0.0e (including) |
Openssl | Openssl | 1.0.0f (including) | 1.0.0f (including) |
Openssl | Openssl | 1.0.0g (including) | 1.0.0g (including) |
Openssl | Openssl | 1.0.0h (including) | 1.0.0h (including) |
Openssl | Openssl | 1.0.0i (including) | 1.0.0i (including) |
Openssl | Openssl | 1.0.0j (including) | 1.0.0j (including) |
Openssl | Openssl | 1.0.0k (including) | 1.0.0k (including) |
Openssl | Openssl | 1.0.0l (including) | 1.0.0l (including) |
Openssl | Openssl | 1.0.0m (including) | 1.0.0m (including) |
Openssl | Openssl | 1.0.0n (including) | 1.0.0n (including) |
Openssl | Openssl | 1.0.0o (including) | 1.0.0o (including) |
Openssl | Openssl | 1.0.1a (including) | 1.0.1a (including) |
Openssl | Openssl | 1.0.1b (including) | 1.0.1b (including) |
Openssl | Openssl | 1.0.1c (including) | 1.0.1c (including) |
Openssl | Openssl | 1.0.1d (including) | 1.0.1d (including) |
Openssl | Openssl | 1.0.1e (including) | 1.0.1e (including) |
Openssl | Openssl | 1.0.1f (including) | 1.0.1f (including) |
Openssl | Openssl | 1.0.1g (including) | 1.0.1g (including) |
Openssl | Openssl | 1.0.1h (including) | 1.0.1h (including) |
Openssl | Openssl | 1.0.1i (including) | 1.0.1i (including) |
Openssl | Openssl | 1.0.1j (including) | 1.0.1j (including) |