CVE Vulnerabilities

CVE-2017-1000415

Improper Certificate Validation

Published: Jan 09, 2018 | Modified: Jan 26, 2018
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates have their expiration (beginning) year extended (delayed) by 100 years.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Matrixssl Matrixssl 3.7.2 (including) 3.7.2 (including)
Matrixssl Ubuntu trusty *
Matrixssl Ubuntu upstream *

Potential Mitigations

References