PT-2011-2599 · Globus · Myproxy+1
Published
2011-02-02
·
Updated
2017-08-17
·
CVE-2011-0738
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
MyProxy versions 5.0 through 5.2
Globus Toolkit versions 5.0.0 through 5.0.2
Description
The issue allows remote attackers to conduct man-in-the-middle (MITM) attacks by spoofing the server, due to improper verification of the
hostname or identity in the X.509 certificate for the myproxy-server. This can occur when executing commands such as myproxy-logon or myproxy-get-delegation with a crafted certificate.Recommendations
For MyProxy versions 5.0 through 5.2, update the software to properly verify the
hostname and identity in the X.509 certificate.
For Globus Toolkit versions 5.0.0 through 5.0.2, ensure that the underlying MyProxy component is updated to address the issue.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Globus Toolkit
Myproxy