PT-2014-3580 · Poco · Poco C++ Libraries
Publicado
2014-04-26
·
Atualizado
2016-12-06
·
CVE-2014-0350
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
POCO C++ Libraries versions prior to 1.4.6p4
Description
The issue allows man-in-the-middle attackers to spoof SSL servers via crafted DNS PTR records that are requested during comparison of a server name to a wildcard domain name in an X.509 certificate. This occurs due to a flaw in the Poco::Net::X509Certificate::verify method in the NetSSL library.
Recommendations
For versions prior to 1.4.6p4, update to version 1.4.6p4 or later to resolve the issue. As a temporary workaround, consider restricting the use of wildcard domain names in X.509 certificates to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Poco C++ Libraries