LWN.net Logo

axis: incorrect certificate validation

Package(s):axis CVE #(s):CVE-2012-5784
Created:February 1, 2013 Updated:March 26, 2013
Description:

From the Fedora advisory:

This update fixes a security vulnerability that caused axis not to verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allowed man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate (CVE-2012-5784).

Alerts:
Fedora FEDORA-2013-1194 2013-02-01
Fedora FEDORA-2013-1222 2013-02-01
Red Hat RHSA-2013:0269-01 2013-02-19
Scientific Linux SL-axis-20130220 2013-02-20
Oracle ELSA-2013-0269 2013-02-20
Red Hat RHSA-2013:0683-01 2013-03-25
CentOS CESA-2013:0683 2013-03-25
Oracle ELSA-2013-0683 2013-03-26
Scientific Linux SL-axis-20130325 2013-03-25

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds