wget: man in the middle attack
| Package(s): | wget | CVE #(s): | CVE-2009-3490 | ||||||||||||||||||||||||||||||||||||||||||||
| Created: | October 6, 2009 | Updated: | December 4, 2009 | ||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Ubuntu advisory: It was discovered that Wget did not correctly handle SSL certificates with zero bytes in the Common Name. A remote attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. | ||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||
