The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2009-09-22T10:00:00
Updated: 2017-09-18T12:57:01
Reserved: 2009-09-22T00:00:00
Link: CVE-2009-3291
JSON object: View
NVD Information
Status : Modified
Published: 2009-09-22T10:30:00.750
Modified: 2018-10-30T16:26:21.043
Link: CVE-2009-3291
JSON object: View
Redhat Information
No data.
CWE