PT-2009-5363 · Perl · Io::Socket::Ssl
Steffen Ullrich
+1
·
Publicado
2009-08-31
·
Atualizado
2011-01-20
·
CVE-2009-3024
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
IO::Socket::SSL versions 1.14 through 1.25
Description:
The certificate checking feature in IO::Socket::SSL has an issue where the
verify hostname of cert function only matches the prefix of a hostname when no wildcard is used. This allows remote attackers to bypass the hostname check for a certificate.Recommendations:
For IO::Socket::SSL versions 1.14 through 1.25, consider updating to a version outside of this range to resolve the issue. As a temporary workaround, restrict the use of the
verify hostname of cert function to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Io::Socket::Ssl