In association with heise online

22 May 2008, 13:36

Stunnel accepts blocked certificates

An update for the stunnel SSL wrapper has been issued in order to close a hole in its handling of x.509 certificates. Due to an error in a function that uses the Online Certificate Status Protocol (OCSP) to check the validity of certificates, an attacker can log in successfully using an already blocked certificate. The developers recommend users of the OCSP function to upgrade to stunnel version 4.24 as soon as possible.

See also:

(mba)

  • Share this article
  • Twitter
  • Facebook
  • digg this
  • submit to slashdot
  • post to delicious
  • StumbleUpon
  • submit to reddit






The H open source

The H Security

The H Internet Toolkit