PT-2011-2599 · Globus · Myproxy+1

Publicado

2011-02-02

·

Atualizado

2017-08-17

·

CVE-2011-0738

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions MyProxy versions 5.0 through 5.2 Globus Toolkit versions 5.0.0 through 5.0.2
Description The issue allows remote attackers to conduct man-in-the-middle (MITM) attacks by spoofing the server, due to improper verification of the hostname or identity in the X.509 certificate for the myproxy-server. This can occur when executing commands such as myproxy-logon or myproxy-get-delegation with a crafted certificate.
Recommendations For MyProxy versions 5.0 through 5.2, update the software to properly verify the hostname and identity in the X.509 certificate. For Globus Toolkit versions 5.0.0 through 5.0.2, ensure that the underlying MyProxy component is updated to address the issue.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-0738

Produtos afetados

Globus Toolkit
Myproxy