CVE-2017-1000417

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
22/01/2018
Last modified:
13/02/2018

Description

MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g. in ExtKeyUsage extension) on X.509 certificates.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:matrixssl:matrixssl:3.7.2:*:*:*:*:*:*:*