Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a use case where a user-provided verification callback returns 1, as demonstrated by acceptance of invalid certificates by nginx.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LibreSSL 安全漏洞
Vulnerability Description
LibreSSL是OpenBSD项目开发的一个OpenSSL加密软件库的分支,也是安全套接层(SSL)和传输层安全(TLS)协议的开源实现。 LibreSSL 2.5.1版本至2.5.3版本中存在安全漏洞,该漏洞源于程序没有充分的验证TLS证书。攻击者可利用该漏洞造成nginx中的TLS-related tests无法启动。
CVSS Information
N/A
Vulnerability Type
N/A