PT-2011-2599 · Globus · Myproxy+1

Published

2011-02-02

·

Updated

2017-08-17

·

CVE-2011-0738

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions MyProxy versions 5.0 through 5.2 Globus Toolkit versions 5.0.0 through 5.0.2
Description The issue allows remote attackers to conduct man-in-the-middle (MITM) attacks by spoofing the server, due to improper verification of the hostname or identity in the X.509 certificate for the myproxy-server. This can occur when executing commands such as myproxy-logon or myproxy-get-delegation with a crafted certificate.
Recommendations For MyProxy versions 5.0 through 5.2, update the software to properly verify the hostname and identity in the X.509 certificate. For Globus Toolkit versions 5.0.0 through 5.0.2, ensure that the underlying MyProxy component is updated to address the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-0738

Affected Products

Globus Toolkit
Myproxy