← Back

CVE-2008-2420

nvd nist
Published: May 23, 2008Modified: Apr 23, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

The OCSP functionality in stunnel before 4.24 does not properly search certificate revocation lists (CRL), which allows remote attackers to bypass intended access restrictions by using revoked certificates.

Affected (54)

Products: Stunnel: Stunnel
1 product
Stunnel
Configuration A
54 vulnerable
Vulnerable SoftwareAffected Versions
Stunnel
Version 3.10
Version 3.11
Version 3.12
Version 3.13
Version 3.14
Version 3.15
Version 3.16
Version 3.17
Version 3.18
Version 3.19
Version 3.20
Version 3.21
Version 3.21a
Version 3.21b
Version 3.21c
Version 3.22
Version 3.23
Version 3.24
Version 3.25
Version 3.26
Version 3.4a
Version 3.5
Version 3.6
Version 3.7
Version 3.8
Version 3.8p1
Version 3.8p2
Version 3.8p3
Version 3.8p4
Version 3.9
Version 4.00
Version 4.01
Version 4.02
Version 4.03
Version 4.04
Version 4.05
Version 4.06
Version 4.07
Version 4.08
Version 4.09
Version 4.10
Version 4.11
Version 4.12
Version 4.13
Version 4.14
Version 4.15
Version 4.16
Version 4.17
Version 4.18
Version 4.19
Version 4.20
Version 4.21
Version 4.22
Version 4.23

Related CWEs

References (24)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.