CVE-2008-2420

Publication date

2008-05-23 15:00:00

Family

mitre

State

PUBLISHED

Description

The OCSP functionality in stunnel before 4.24 does not properly search certificate revocation lists (CRL), which allows remote attackers to bypass intended access restrictions by using revoked certificates.