Portage 'urlopen()' SSL Certificate Validation Security Bypass Vulnerability
BID:59878
Info
Portage 'urlopen()' SSL Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 59878 |
| Class: | Design Error |
| CVE: |
CVE-2013-2100 |
| Remote: | Yes |
| Local: | No |
| Published: | May 15 2013 12:00AM |
| Updated: | Jul 15 2015 01:07AM |
| Credit: | Jason A. Donenfeld |
| Vulnerable: |
Gentoo sys-apps/portage 2.1.4.5 Gentoo sys-apps/portage 2.1.4.4 Gentoo sys-apps/portage 2.1.3.11 Gentoo sys-apps/portage 2.1.3.10 Gentoo Linux |
| Not Vulnerable: | |
Discussion
Portage 'urlopen()' SSL Certificate Validation Security Bypass Vulnerability
Portage is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates from the server.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Portage is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates from the server.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Exploit / POC
Portage 'urlopen()' SSL Certificate Validation Security Bypass Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Portage 'urlopen()' SSL Certificate Validation Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Portage 'urlopen()' SSL Certificate Validation Security Bypass Vulnerability
References:
References: