Vulnerability Description
MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates have their expiration (beginning) year extended (delayed) by 100 years.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Matrixssl | Matrixssl | 3.7.2 |
Related Weaknesses (CWE)
References
- https://www.ieee-security.org/TC/SP2017/papers/231.pdfThird Party Advisory
- https://www.youtube.com/watch?v=FW--c_F_cY8Third Party Advisory
- https://www.ieee-security.org/TC/SP2017/papers/231.pdfThird Party Advisory
- https://www.youtube.com/watch?v=FW--c_F_cY8Third Party Advisory
FAQ
What is CVE-2017-1000415?
CVE-2017-1000415 is a vulnerability with a CVSS score of 5.9 (MEDIUM). MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates have their expiration (beginning) year extended (delay...
How severe is CVE-2017-1000415?
CVE-2017-1000415 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-1000415?
Check the references section above for vendor advisories and patch information. Affected products include: Matrixssl Matrixssl.