{"id":"CVE-2018-8970","details":"The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does not support a certain special case of a zero name length, which causes silent omission of hostname verification, and consequently allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. NOTE: the LibreSSL documentation indicates that this special case is supported, but the BoringSSL documentation does not.","modified":"2026-08-27T08:14:57.553189Z","published":"2018-03-24T21:29:00.227Z","related":["openSUSE-SU-2024:10985-1"],"references":[{"type":"ADVISORY","url":"https://boringssl.googlesource.com/boringssl/+/e759a9cd84198613199259dbed401f4951747cff"},{"type":"ADVISORY","url":"https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-2.7.1-relnotes.txt"},{"type":"FIX","url":"https://github.com/libressl-portable/openbsd/commit/0654414afcce51a16d35d05060190a3ec4618d42"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libressl/openbsd","events":[{"introduced":"0"},{"fixed":"0654414afcce51a16d35d05060190a3ec4618d42"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-8970.json","vanir_signatures_modified":"2026-08-27T08:14:57Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"124066432240387748490862556255300495937","length":675},"id":"CVE-2018-8970-1fc07437","signature_type":"Function","signature_version":"v1","source":"https://github.com/libressl/openbsd/commit/0654414afcce51a16d35d05060190a3ec4618d42","target":{"file":"src/lib/libcrypto/x509/x509_vpm.c","function":"int_x509_param_set_hosts"}},{"source":"https://github.com/libressl/openbsd/commit/0654414afcce51a16d35d05060190a3ec4618d42","target":{"file":"src/lib/libcrypto/x509/x509_vpm.c"},"deprecated":false,"digest":{"line_hashes":["70783060215513847624548349568642194857","288999768788510714880779861120358134171","197705374756881059557087188571414980896","87837263733689742431856688096169499200"],"threshold":0.9},"id":"CVE-2018-8970-3ec5e240","signature_type":"Line","signature_version":"v1"}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/libressl/portable","events":[{"introduced":"c22031f0fc020e6de9b2ef4de16fa10c674ec8fa"},{"last_affected":"c22031f0fc020e6de9b2ef4de16fa10c674ec8fa"}],"database_specific":{"cpe":"cpe:2.3:a:openbsd:libressl:2.7.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.7.0"},{"last_affected":"2.7.0"}],"source":"CPE_STRING"}}],"versions":["2.7.0","v2.7.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-8970.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}