SA-2023-040 - OpenSSL Invalid Certificate Policies (CVE-2023-0465)
Summary Applications that use a non-default option to verify certificates may be vulnerable to an attack from a malicious CA. OpenSSL ignores Invalid certificate policies in leaf certificates. A malic...