Hide Forgot
Botan 2.19.2 and older failed to verify that an authorized responder certificate embedded in an OCSP response is authorized by the issuing CA. As a result, any valid signature by an embedded certificate passed the check and was allowed to make claims about the revocation status of certificates of any CA.
Created botan2 tracking bugs for this issue: Affects: fedora-all [bug 2143418]