Vulnerability Details CVE-2009-3291
The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.027
EPSS Ranking 85.5%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2009-3291