LWN.net Logo

perl-IO-Socket-SSL: site spoofing

Package(s):perl-IO-Socket-SSL CVE #(s):
Created:July 20, 2009 Updated:July 22, 2009
Description: The perl-IO-Socket-SSL library only checks the prefix of hostnames when performing certificate matching, making site-spoofing attacks possible.
Alerts:
Fedora FEDORA-2009-7435 2009-07-11
Fedora FEDORA-2009-7544 2009-07-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds