CVE-2017-1000415

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
09/01/2018
Last modified:
26/01/2018

Description

MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates have their expiration (beginning) year extended (delayed) by 100 years.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:matrixssl:matrixssl:3.7.2:*:*:*:*:*:*:*