Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2003-0960

EPSS 0.26% · P50
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2003-0960

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
OpenCA before 0.9.1.4 does not use the correct certificate in a chain to check the serial, which could cause OpenCA to accept revoked or expired certificates.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
OpenCA多个签名验证漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OpenCA是一款提供PKI架构和相关项目开发的项目实现。 OpenCA存在多个漏洞,可导致修改的或过期的证书被接受。 具体问题如下: 1、OpenCA有一个通用加密操作的库-crypto-utils.lib,这个库包含一个函数判断用于建立PKCS#7签名的证书序列,函数使用这个序列装载和返回证书。不过这个函数错误的使用OpenCA::PKCS7接口。 2、加密库crypto-utils.lib使用所有包含签名的证书来建议签名者证书的X.509对象,结果是来自证书链之一的证书建立的对象可以是任意的。 3、
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2003-0960

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2003-0960

登录查看更多情报信息。

Same Patch Batch · n/a · 2003-12-02 · 10 CVEs total

CVE-2003-0914ISC BIND否定应答缓冲污染远程拒绝服务攻击漏洞
CVE-2003-0961Linux kernel do_brk()参数边界检查不充分漏洞
CVE-2003-0967FreeRADIUS Tag头字段堆破坏漏洞
CVE-2003-0968FreeRADIUS缓冲区溢出漏洞
CVE-2003-0970Sun Fire系统恶意ARP包远程拒绝服务攻击漏洞
CVE-2003-0971GnuPG ElGamal签名密钥私钥信息泄露漏洞
CVE-2003-0972GNU Screen转义序列缓冲区溢出漏洞
CVE-2003-0973Apache mod_python模块畸形查询远程拒绝服务攻击漏洞
CVE-2003-0974Applied Watch Command Center验证绕过漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2003-0960

No comments yet


Leave a comment