Vulnerability Description
OpenCA before 0.9.1.4 does not use the correct certificate in a chain to check the serial, which could cause OpenCA to accept revoked or expired certificates.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openca | Openca | 0.8.0 |
References
FAQ
What is CVE-2003-0960?
CVE-2003-0960 is a vulnerability with a CVSS score of 7.5 (HIGH). OpenCA before 0.9.1.4 does not use the correct certificate in a chain to check the serial, which could cause OpenCA to accept revoked or expired certificates.
How severe is CVE-2003-0960?
CVE-2003-0960 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-0960?
Check the references section above for vendor advisories and patch information. Affected products include: Openca Openca.