OpenCA Multiple Signature Validation Bypass

This script is Copyright (C) 2004-2011 Tenable Network Security, Inc.


Synopsis :

The remote application is vulnerable to several flaws.

Description :

The remote host seems to be running an older version of OpenCA.

It is reported that OpenCA versions up to and incluing 0.9.1.3 contains
multiple flaws that may allow revoked or expired certificates to be
accepted as valid.

Solution :

Upgrade to the newest version of this software.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 5.5
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: CGI abuses

Nessus Plugin ID: 14714 ()

Bugtraq ID: 9123

CVE ID: CVE-2003-0960