|
|
| |
|
| |
python-bugzilla: missing certificate verification
| Package(s): | python-bugzilla |
CVE #(s): | CVE-2013-2191
|
| Created: | July 8, 2013 |
Updated: | July 10, 2013 |
| Description: |
From the SUSE bugzilla entry:
It was found that python-bugzilla, a Python library for interacting with
Bugzilla instances over XML-RPC functionality, did not perform X.509
certificate verification when using secured SSL connection. A man-in-the-middle
(MiTM) attacker could use this flaw to spoof Bugzilla server via an arbitrary
certificate. |
| Alerts: |
|
( Log in to post comments)
|
|
|