Leaf Certificate Verification Flaw in LibreSSL and OpenBSD
CVE-2022-48437
5.3MEDIUM
Summary
A flaw exists in the leaf certificate verification process within LibreSSL and OpenBSD, specifically related to x509/x509_verify.c. When the function x509_verify_ctx_add_chain encounters an error during verification, it fails to properly log the error, resulting in inappropriate error messages being returned. This issue is exacerbated when a verification callback is in place, which instructs the verifier to continue processing upon facing an invalid certificate, potentially compromising certificate trust and validation processes.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved