LWN.net Logo

perl-IO-Socket-SSL: invalid certificate checking

Package(s):perl-IO-Socket-SSL CVE #(s):CVE-2009-3024
Created:December 7, 2009 Updated:January 17, 2011
Description:

From the Mandriva advisory:

The verify_hostname_of_cert function in the certificate checking feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through 1.25 only matches the prefix of a hostname when no wildcard is used, which allows remote attackers to bypass the hostname check for a certificate (CVE-2009-3024).

Alerts:
Gentoo 201101-06 2011-01-16
Mandriva MDVSA-2009:252-1 2009-12-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds