|
|
| |
|
| |
perl-IO-Socket-SSL: invalid certificate checking
| Package(s): | perl-IO-Socket-SSL |
CVE #(s): | CVE-2009-3024
|
| Created: | December 7, 2009 |
Updated: | January 17, 2011 |
| Description: |
From the Mandriva advisory:
The verify_hostname_of_cert function in the certificate checking
feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through 1.25 only
matches the prefix of a hostname when no wildcard is used, which
allows remote attackers to bypass the hostname check for a certificate
(CVE-2009-3024).
|
| Alerts: |
|
( Log in to post comments)
|
|
|