CNCVE编号:CNCVE-20010338 CVE编号:CVE-2001-0338 安全级别:高 漏洞中文描述: Internet Explorer 5.5 以及更早的版本当证书废除列表(CRL,Certificate Revocation List)检查开启时,也不能验证数字证书,这使得远程攻击者可以欺骗被信任的Web站点,也就是“服务器证书验证漏洞”。 漏洞英文描述: Internet Explorer 5.5 and earlier does not properly validate digital certificates when Certificate Revocation List (CRL) checking is enabled, which could allow remote attackers to spoof trusted web sites, aka the "Server certificate validation vulnerability. 漏洞参考: MS:MS01-027 URL:http://www.microsoft.com/technet/security/bulletin/MS01-027.asp 系统类型: Unix/Linux Win95/98/ME Win2000/NT Apple 漏洞类型:权限有效性检查错误