The OCSP functionality in stunnel before 4.24 does not properly search certificate revocation lists (CRL), which allows remote attackers to bypass intended access restrictions by using revoked certificates.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2008-05-23T15:00:00

Updated: 2024-08-07T08:58:02.605Z

Reserved: 2008-05-23T00:00:00

Link: CVE-2008-2420

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2008-05-23T15:32:00.000

Modified: 2017-08-08T01:31:01.950

Link: CVE-2008-2420

cve-icon Redhat

Severity : Moderate

Publid Date: 2008-05-19T00:00:00Z

Links: CVE-2008-2420 - Bugzilla