Links SSL Certificate Verification Security Weakness
BID:33108
Info
Links SSL Certificate Verification Security Weakness
| Bugtraq ID: | 33108 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 01 2009 12:00AM |
| Updated: | Jun 26 2012 06:20PM |
| Credit: | Neil Moore |
| Vulnerable: |
Twibright Labs Links 2.2 Pardus Linux 2009 0 Gentoo Linux |
| Not Vulnerable: | |
Discussion
Links SSL Certificate Verification Security Weakness
Links is prone to a security weakness because it fails to verify SSL certificates presented by a remote server.
An attacker can exploit this weakness to masquerade as a legitimate server using a man-in-the-middle attack or to launch other attacks such as phishing.
Links 2.2 is vulnerable; other versions may be affected as well.
Links is prone to a security weakness because it fails to verify SSL certificates presented by a remote server.
An attacker can exploit this weakness to masquerade as a legitimate server using a man-in-the-middle attack or to launch other attacks such as phishing.
Links 2.2 is vulnerable; other versions may be affected as well.
Exploit / POC
Links SSL Certificate Verification Security Weakness
An attacker use readily available tools to carry out this attack.
An attacker use readily available tools to carry out this attack.
Solution / Fix
Links SSL Certificate Verification Security Weakness
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Links SSL Certificate Verification Security Weakness
References:
References:
- Debian Bug report logs - #510417 (Neil Moore
) - Links Homepage (Links)