qpid-proton: TLS to plaintext downgrade
| Package(s): | qpid-proton | CVE #(s): | CVE-2016-2166 | ||||
| Created: | April 15, 2016 | Updated: | April 20, 2016 | ||||
| Description: | From the Red Hat bugzilla entry:
Messaging applications using the Proton Python API to provision an SSL/TLS encrypted TCP connection may actually instantiate a non-encrypted connection without notice if SSL support is unavailable. This will result in all messages being sent in the clear without the knowledge of the user. | ||||||
| Alerts: |
| ||||||
