CVE-2008-2420
Mandriva Linux Security Advisory 2008-168
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The OCSP functionality in stunnel before 4.24 does not properly search certificate revocation lists (CRL), which allows remote attackers to bypass intended access restrictions by using revoked certificates.
Vulnerabilidad en la funcionalidad OCSP en stunnel anteriores a 4.24 no busca de forma adecuada la lista de revocación de certificado (CRL), que permite a atacantes remotos intentar saltarse las restricciones de acceso utilizando certificados revocados.
A vulnerability was found in the OCSP search functionality in stunnel that could allow a remote attacker to use a revoked certificate that would be successfully authenticated by stunnel. This flaw only concerns users who have enabled OCSP validation in stunnel. The updated packages have been patched to correct this issue.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-05-23 CVE Reserved
- 2008-05-23 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/30425 | Third Party Advisory | |
http://secunia.com/advisories/31438 | Third Party Advisory | |
http://stunnel.mirt.net/pipermail/stunnel-announce/2008-May/000035.html | Mailing List | |
http://www.vupen.com/english/advisories/2008/1569/references | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42528 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/bid/29309 | 2017-08-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.4a Search vendor "Stunnel" for product "Stunnel" and version "3.4a" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.5 Search vendor "Stunnel" for product "Stunnel" and version "3.5" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.6 Search vendor "Stunnel" for product "Stunnel" and version "3.6" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.7 Search vendor "Stunnel" for product "Stunnel" and version "3.7" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.8 Search vendor "Stunnel" for product "Stunnel" and version "3.8" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.8p1 Search vendor "Stunnel" for product "Stunnel" and version "3.8p1" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.8p2 Search vendor "Stunnel" for product "Stunnel" and version "3.8p2" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.8p3 Search vendor "Stunnel" for product "Stunnel" and version "3.8p3" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.8p4 Search vendor "Stunnel" for product "Stunnel" and version "3.8p4" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.9 Search vendor "Stunnel" for product "Stunnel" and version "3.9" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.10 Search vendor "Stunnel" for product "Stunnel" and version "3.10" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.11 Search vendor "Stunnel" for product "Stunnel" and version "3.11" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.12 Search vendor "Stunnel" for product "Stunnel" and version "3.12" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.13 Search vendor "Stunnel" for product "Stunnel" and version "3.13" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.14 Search vendor "Stunnel" for product "Stunnel" and version "3.14" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.15 Search vendor "Stunnel" for product "Stunnel" and version "3.15" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.16 Search vendor "Stunnel" for product "Stunnel" and version "3.16" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.17 Search vendor "Stunnel" for product "Stunnel" and version "3.17" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.18 Search vendor "Stunnel" for product "Stunnel" and version "3.18" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.19 Search vendor "Stunnel" for product "Stunnel" and version "3.19" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.20 Search vendor "Stunnel" for product "Stunnel" and version "3.20" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.21 Search vendor "Stunnel" for product "Stunnel" and version "3.21" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.21a Search vendor "Stunnel" for product "Stunnel" and version "3.21a" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.21b Search vendor "Stunnel" for product "Stunnel" and version "3.21b" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.21c Search vendor "Stunnel" for product "Stunnel" and version "3.21c" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.22 Search vendor "Stunnel" for product "Stunnel" and version "3.22" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.23 Search vendor "Stunnel" for product "Stunnel" and version "3.23" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.24 Search vendor "Stunnel" for product "Stunnel" and version "3.24" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.25 Search vendor "Stunnel" for product "Stunnel" and version "3.25" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 3.26 Search vendor "Stunnel" for product "Stunnel" and version "3.26" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.00 Search vendor "Stunnel" for product "Stunnel" and version "4.00" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.01 Search vendor "Stunnel" for product "Stunnel" and version "4.01" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.02 Search vendor "Stunnel" for product "Stunnel" and version "4.02" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.03 Search vendor "Stunnel" for product "Stunnel" and version "4.03" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.04 Search vendor "Stunnel" for product "Stunnel" and version "4.04" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.05 Search vendor "Stunnel" for product "Stunnel" and version "4.05" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.06 Search vendor "Stunnel" for product "Stunnel" and version "4.06" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.07 Search vendor "Stunnel" for product "Stunnel" and version "4.07" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.08 Search vendor "Stunnel" for product "Stunnel" and version "4.08" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.09 Search vendor "Stunnel" for product "Stunnel" and version "4.09" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.10 Search vendor "Stunnel" for product "Stunnel" and version "4.10" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.11 Search vendor "Stunnel" for product "Stunnel" and version "4.11" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.12 Search vendor "Stunnel" for product "Stunnel" and version "4.12" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.13 Search vendor "Stunnel" for product "Stunnel" and version "4.13" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.14 Search vendor "Stunnel" for product "Stunnel" and version "4.14" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.15 Search vendor "Stunnel" for product "Stunnel" and version "4.15" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.16 Search vendor "Stunnel" for product "Stunnel" and version "4.16" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.17 Search vendor "Stunnel" for product "Stunnel" and version "4.17" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.18 Search vendor "Stunnel" for product "Stunnel" and version "4.18" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.19 Search vendor "Stunnel" for product "Stunnel" and version "4.19" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.20 Search vendor "Stunnel" for product "Stunnel" and version "4.20" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.21 Search vendor "Stunnel" for product "Stunnel" and version "4.21" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.22 Search vendor "Stunnel" for product "Stunnel" and version "4.22" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 4.23 Search vendor "Stunnel" for product "Stunnel" and version "4.23" | - |
Affected
|