Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2015-1793 Details

Description

The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid leaf certificate.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://fortiguard.com/advisory/2015-07-09-cve-2015-1793-openssl-alternative-chains-certificate-forgery CVE
http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2015-008.txt.asc CVE
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10694 CVE
http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161747.html CVE
http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161782.html CVE

see all 62 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-2547PK - Security Features[email protected]

Affected Products

ProductVersions
oracle supply chain products suite
6.1.2.2
6.1.3.0
6.2.0

CPE

  • cpe:2.3:a:oracle:supply_chain_products_suite:6.1.2.2:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:supply_chain_products_suite:6.1.3.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:supply_chain_products_suite:6.2.0:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
oracle jd edwards enterpriseone tools
9.1
9.2

CPE

  • cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.1:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
openssl openssl
1.0.1n
1.0.1o
1.0.2b
1.0.2c

CPE

  • cpe:2.3:a:openssl:openssl:1.0.1n:*:*:*:*:*:*:*
  • cpe:2.3:a:openssl:openssl:1.0.1o:*:*:*:*:*:*:*
  • cpe:2.3:a:openssl:openssl:1.0.2b:*:*:*:*:*:*:*
  • cpe:2.3:a:openssl:openssl:1.0.2c:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
oracle opus 10g ethernet switch family
<= 2.0.0.6

CPE

  • cpe:2.3:o:oracle:opus_10g_ethernet_switch_family:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

34 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2015-1793
NVD Published Date:
Jul 9, 2015
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2015-1793 Details - Not Deferred