CVE-2021-44273
Summary
| CVE | CVE-2021-44273 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-23 12:15:00 UTC |
| Updated | 2023-09-13 00:15:00 UTC |
| Description | e2guardian v5.4.x <= v5.4.3r is affected by missing SSL certificate validation in the SSL MITM engine. In standalone mode (i.e., acting as a proxy or a transparent proxy), with SSL MITM enabled, e2guardian, if built with OpenSSL v1.1.x, did not validate hostnames in certificates of the web servers that it connected to, and thus was itself vulnerable to MITM attacks. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
E2bn |
E2guardian |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 3564-1] e2guardian security update |
MLIST |
lists.debian.org |
|
| Fix bug #707 cert hostnames not being checked · e2guardian/e2guardian@eae46a7 · GitHub |
MISC |
github.com |
|
| oss-security - CVE-2021-44273: e2guardian did not validate TLS hostnames |
MLIST |
www.openwall.com |
|
| v5.4: Missing SSL hostname check · Issue #707 · e2guardian/e2guardian · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179424 Debian Security Update for e2guardian (CVE-2021-44273)
- 502559 Alpine Linux Security Update for e2guardian
- 504710 Alpine Linux Security Update for e2guardian
- 6000040 Debian Security Update for e2guardian (DLA 3564-1)