CVE-2022-48437

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-48437
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-48437.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-48437
Published
2023-04-12T05:15:07Z
Modified
2025-02-10T19:48:11.570338Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

An issue was discovered in x509/x509verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001. x509verifyctxadd_chain does not store errors that occur during leaf certificate verification, and therefore an incorrect error is returned. This behavior occurs when there is an installed verification callback that instructs the verifier to continue upon detecting an invalid certificate.

References

Affected packages

Git / github.com/libressl-portable/portable

Affected ranges

Type
GIT
Repo
https://github.com/libressl-portable/portable
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/openbsd/src
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

v2.*

v2.1.2
v2.1.3
v2.1.4
v2.2.0
v2.2.1
v2.2.2
v2.3.0
v2.3.1
v2.3.2
v2.4.0
v2.4.1
v2.5.0
v2.5.1
v2.5.2
v2.6.0
v2.6.1
v2.6.2
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0

v3.*

v3.0.0
v3.0.1
v3.1.0
v3.2.0
v3.2.1
v3.3.0
v3.3.1
v3.3.2
v3.4.0
v3.5.0
v3.5.1
v3.6.0