CVE-2008-2420
Publication date 23 May 2008
Last updated 24 July 2024
Ubuntu priority
The OCSP functionality in stunnel before 4.24 does not properly search certificate revocation lists (CRL), which allows remote attackers to bypass intended access restrictions by using revoked certificates.