Description
LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a use case where a user-provided verification callback returns 1, as demonstrated by acceptance of invalid certificates by nginx.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 alpine v3.7 | | =2.1.4-r0 || =2.2.0-r0 || =2.2.1-r0 || =2.2.2-r0 || =2.2.3-r0 || =2.2.4-r0 || =2.2.5-r0 || =2.2.6-r0 || =2.2.6-r1 || =2.4.2-r0 || =2.4.3-r0 || =2.4.3-r2 || =2.4.4-r0 || =2.4.5-r0 || =2.5.3-r0 || >=0 <2.5.3-r1 | 2.5.3-r1 |
 alpine v3.11 | | =2.1.4-r0 || =2.2.0-r0 || =2.2.1-r0 || =2.2.2-r0 || =2.2.3-r0 || =2.2.4-r0 || =2.2.5-r0 || =2.2.6-r0 || =2.2.6-r1 || =2.4.2-r0 || =2.4.3-r0 || =2.4.3-r2 || =2.4.4-r0 || =2.4.5-r0 || =2.5.3-r0 || >=0 <2.5.3-r1 | 2.5.3-r1 |
 alpine v3.12 | | =2.1.4-r0 || =2.2.0-r0 || =2.2.1-r0 || =2.2.2-r0 || =2.2.3-r0 || =2.2.4-r0 || =2.2.5-r0 || =2.2.6-r0 || =2.2.6-r1 || =2.4.2-r0 || =2.4.3-r0 || =2.4.3-r2 || =2.4.4-r0 || =2.4.5-r0 || =2.5.3-r0 || >=0 <2.5.3-r1 | 2.5.3-r1 |
 alpine v3.6 | | =2.1.4-r0 || =2.2.0-r0 || =2.2.1-r0 || =2.2.2-r0 || =2.2.3-r0 || =2.2.4-r0 || =2.2.5-r0 || =2.2.6-r0 || =2.2.6-r1 || =2.4.2-r0 || =2.4.3-r0 || =2.4.3-r2 || =2.4.4-r0 || =2.4.5-r0 || =2.5.3-r0 || >=0 <2.5.3-r1 | 2.5.3-r1 |
 alpine v3.10 | | =2.1.4-r0 || =2.2.0-r0 || =2.2.1-r0 || =2.2.2-r0 || =2.2.3-r0 || =2.2.4-r0 || =2.2.5-r0 || =2.2.6-r0 || =2.2.6-r1 || =2.4.2-r0 || =2.4.3-r0 || =2.4.3-r2 || =2.4.4-r0 || =2.4.5-r0 || =2.5.3-r0 || >=0 <2.5.3-r1 | 2.5.3-r1 |
 alpine v3.9 | | =2.1.4-r0 || =2.2.0-r0 || =2.2.1-r0 || =2.2.2-r0 || =2.2.3-r0 || =2.2.4-r0 || =2.2.5-r0 || =2.2.6-r0 || =2.2.6-r1 || =2.4.2-r0 || =2.4.3-r0 || =2.4.3-r2 || =2.4.4-r0 || =2.4.5-r0 || =2.5.3-r0 || >=0 <2.5.3-r1 | 2.5.3-r1 |
 alpine v3.8 | | =2.1.4-r0 || =2.2.0-r0 || =2.2.1-r0 || =2.2.2-r0 || =2.2.3-r0 || =2.2.4-r0 || =2.2.5-r0 || =2.2.6-r0 || =2.2.6-r1 || =2.4.2-r0 || =2.4.3-r0 || =2.4.3-r2 || =2.4.4-r0 || =2.4.5-r0 || =2.5.3-r0 || >=0 <2.5.3-r1 | 2.5.3-r1 |
 alpine v3.13 | | =2.1.4-r0 || =2.2.0-r0 || =2.2.1-r0 || =2.2.2-r0 || =2.2.3-r0 || =2.2.4-r0 || =2.2.5-r0 || =2.2.6-r0 || =2.2.6-r1 || =2.4.2-r0 || =2.4.3-r0 || =2.4.3-r2 || =2.4.4-r0 || =2.4.5-r0 || =2.5.3-r0 || >=0 <2.5.3-r1 | 2.5.3-r1 |