|
|
| |
|
| |
zabbix: man-in-the-middle attacks
| Package(s): | zabbix |
CVE #(s): | CVE-2012-6086
|
| Created: | September 30, 2013 |
Updated: | October 2, 2013 |
| Description: |
From the Red Hat bugzilla:
A security flaw was found in the way Zabbix, an open-source monitoring solution for IT infrastructure, used (lib)cURL's CURLOPT_SSL_VERIFYHOST variable, when doing certificate validation (value of '1' meaning only check for the existence of a common name was used instead of value '2' - which also checks if the particular common name matches the requested hostname of the server). A rogue service could use this flaw to conduct man-in-the-middle (MiTM) attacks. |
| Alerts: |
|
( Log in to post comments)
|
|
|