PT-2011-1504 · Perl · Io::Socket::Ssl

Josh Bressers

+1

·

Published

2011-01-14

·

Updated

2011-10-14

·

CVE-2010-4334

CVSS v2.0

4.0

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions IO::Socket::SSL module version 1.35
Description The issue allows remote attackers to bypass intended certificate restrictions due to the module failing open to VERIFY NONE instead of throwing an error when a ca file/ca path cannot be verified. This occurs when verify mode is not VERIFY NONE.
Recommendations For IO::Socket::SSL module version 1.35, consider updating the verify mode settings to ensure proper error handling when ca file/ca path verification fails, or apply a patch if available, to prevent the module from failing open to VERIFY NONE.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-4334

Affected Products

Io::Socket::Ssl