Perl IO::Socket::SSL 'verify_hostname_of_cert()' Security Bypass Vulnerability
BID:35587
Info
Perl IO::Socket::SSL 'verify_hostname_of_cert()' Security Bypass Vulnerability
| Bugtraq ID: | 35587 |
| Class: | Design Error |
| CVE: |
CVE-2009-3024 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 03 2009 12:00AM |
| Updated: | Apr 13 2015 09:35PM |
| Credit: | Marc Lehmann |
| Vulnerable: |
SuSE SUSE Linux Enterprise 11 S.u.S.E. openSUSE 11.1 Pardus Linux 2009 0 Pardus Linux 2008 0 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux CPAN IO::Socket::SSL 1.25 |
| Not Vulnerable: |
CPAN IO::Socket::SSL 1.26 |
Discussion
Perl IO::Socket::SSL 'verify_hostname_of_cert()' Security Bypass Vulnerability
The IO::Socket::SSL module for Perl is prone to a security-bypass vulnerability because the application fails to properly validate certificate hostnames.
Successfully exploiting this issue allows attackers to bypass certain security restrictions, which may aid in further attacks.
Versions prior to IO::Socket::SSL 1.26 are vulnerable.
The IO::Socket::SSL module for Perl is prone to a security-bypass vulnerability because the application fails to properly validate certificate hostnames.
Successfully exploiting this issue allows attackers to bypass certain security restrictions, which may aid in further attacks.
Versions prior to IO::Socket::SSL 1.26 are vulnerable.
Exploit / POC
Perl IO::Socket::SSL 'verify_hostname_of_cert()' Security Bypass Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
Perl IO::Socket::SSL 'verify_hostname_of_cert()' Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2009.0 x86_64
MandrakeSoft Enterprise Server 5
Mandriva Linux Mandrake 2009.0
MandrakeSoft Enterprise Server 5 x86_64
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva perl-IO-Socket-SSL-1.15-1.1mdv2009.0.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-IO-Socket-SSL-1.15-1.2mdv2009.0.noarch.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5
-
Mandriva perl-IO-Socket-SSL-1.15-1.1mdvmes5.noarch.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.0
-
Mandriva perl-IO-Socket-SSL-1.15-1.1mdv2009.0.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-IO-Socket-SSL-1.15-1.2mdv2009.0.noarch.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva perl-IO-Socket-SSL-1.15-1.1mdvmes5.noarch.rpm
http://www.mandriva.com/en/download/
References
Perl IO::Socket::SSL 'verify_hostname_of_cert()' Security Bypass Vulnerability
References:
References:
- IO-Socket-SSL Homepage (CPAN)
- IO::Socket::SSL 1.26 Changelog (CPAN)