Summary
Applications that use a non-default option to verify certificates may be vulnerable to an attack from a malicious CA. OpenSSL ignores Invalid certificate policies in leaf certificates. A malicious CA could use this to assert invalid certificate policies in order to circumvent policy checking on the certificate altogether. If you pass the `-policy' argument to the command line utilities, policy processing can be enabled.
Products Potentially Affected
OS/Product |
Exposure |
Network OS |
No |
|
Repair Recommendations
None.
Please see the full security advisory article here for more details and updates.