LWN.net Logo

qpid: SSL certificate spoofing

Package(s):qpid CVE #(s):CVE-2013-1909
Created:July 12, 2013 Updated:July 17, 2013
Description:

From the Red Hat advisory:

It was discovered that the Qpid Python client library for AMQP did not properly perform TLS/SSL certificate validation of the remote server's certificate, even when the 'ssl_trustfile' connection option was specified. A rogue server could use this flaw to conduct man-in-the-middle attacks, possibly leading to the disclosure of sensitive information.

Alerts:
Red Hat RHSA-2013:1024-01 2013-07-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds