CVE-2017-1000417: XSS
Published Jan 22, 2018
·Updated
MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g. in ExtKeyUsage extension) on X.509 certificates.
Affected Software
1 affected component
MatrixSSL MatrixSSL=3.7.2
Event History
Jan 22, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-1000417?
CVE-2017-1000417 is classified as a medium severity vulnerability due to its potential for spoofing X.509 certificate OIDs.
2
How do I fix CVE-2017-1000417?
To mitigate CVE-2017-1000417, upgrade MatrixSSL to a version later than 3.7.2 where the OID comparison logic is improved.
3
What impact does CVE-2017-1000417 have on X.509 certificates?
CVE-2017-1000417 can lead to spoofing of OIDs, which compromises the integrity of X.509 certificates.
4
Which version of MatrixSSL is affected by CVE-2017-1000417?
MatrixSSL version 3.7.2 is the only version explicitly affected by CVE-2017-1000417.
5
Who is affected by CVE-2017-1000417?
Users and applications relying on MatrixSSL version 3.7.2 for secure communications are affected by CVE-2017-1000417.