|
|
| |
|
| |
axis: incorrect certificate validation
| Package(s): | axis |
CVE #(s): | CVE-2012-5784
|
| Created: | February 1, 2013 |
Updated: | March 26, 2013 |
| Description: |
From the Fedora advisory:
This update fixes a security vulnerability that caused axis not to verify that the server hostname
matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509
certificate, which allowed man-in-the-middle attackers to spoof SSL servers via an arbitrary valid
certificate (CVE-2012-5784). |
| Alerts: |
|
( Log in to post comments)
|
|
|