PT-2012-4719 · Apache · Apache Libcloud
Martin Georgiev
+2
·
Published
2012-11-04
·
Updated
2024-02-14
·
CVE-2012-3446
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Libcloud versions prior to 0.11.1
Description
The issue arises from an incorrect regular expression used during the verification process of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate. This allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
Recommendations
For versions prior to 0.11.1, update to version 0.11.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of SSL connections to trusted servers until the update is applied.
Exploit
Fix
RCE
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Libcloud