New OpenSSL Flaw Is No Heartbleed
ID: cde50017-21c4-58e9-9ec2-6791fdbd4ad6
STIX ID: report--cde50017-21c4-58e9-9ec2-6791fdbd4ad6
Feed Name: Security Ledger
OpenSSL disclosed a high-severity certificate-validation flaw (CVE-2015-1793) that can enable forged certificates by falling back to an alternative certificate chain when initial chain building fails; affected releases include OpenSSL 1.0.2b/1.0.2c and 1.0.1n/1.0.1o and users are advised to upgrade to patched versions (1.0.2d or 1.0.1p). The report emphasizes limited real-world impact because common browsers and SSL derivatives typically do not use the affected OpenSSL builds and successful exploitation requires both access to a vulnerable client and delivery of the forged certificate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
