PT-2011-2511 · Perl · Libwww-Perl
Aaron
·
Published
2011-05-13
·
Updated
2018-10-30
·
CVE-2011-0633
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
libwww-perl (LWP) versions prior to 6.00
Description
The issue allows remote attackers to conduct man-in-the-middle (MITM) attacks by spoofing servers due to inadequate validation of SSL certificates when the If-SSL-Cert-Subject header is not set. This occurs because the Net::HTTPS module does not enable full validation of SSL certificates by default in such environments.
Recommendations
For versions prior to 6.00, update to version 6.00 or later to enable full validation of SSL certificates by default. As a temporary workaround, consider configuring the environment to set the If-SSL-Cert-Subject header to ensure proper validation of hostnames.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libwww-Perl