|
|
| |
|
| |
qpid: SSL certificate spoofing
| Package(s): | qpid |
CVE #(s): | CVE-2013-1909
|
| Created: | July 12, 2013 |
Updated: | July 17, 2013 |
| Description: |
From the Red Hat advisory:
It was discovered that the Qpid Python client library for AMQP did not properly perform TLS/SSL certificate validation of the remote server's certificate, even when the 'ssl_trustfile' connection option was specified. A rogue server could use this flaw to conduct man-in-the-middle attacks, possibly leading to the disclosure of sensitive information. |
| Alerts: |
|
( Log in to post comments)
|
|
|