PT-2012-4719 · Apache · Apache Libcloud

Martin Georgiev

+2

·

Published

2012-11-04

·

Updated

2024-02-14

·

CVE-2012-3446

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Libcloud versions prior to 0.11.1
Description The issue arises from an incorrect regular expression used during the verification process of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate. This allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
Recommendations For versions prior to 0.11.1, update to version 0.11.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of SSL connections to trusted servers until the update is applied.

Exploit

Fix

RCE

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2012-3446
GHSA-PRCQ-52F8-FP44
PYSEC-2012-12

Affected Products

Apache Libcloud