An issue was found in certificate validation using OCSP responses caused by not verifying the serial length, which can falsely report a certificate as valid (CVE-2016-7444).
{ "section": "core" }