python-bugzilla CVE-2013-2191 SSL Certificate Validation Security Bypass Vulnerability
BID:60687
Info
python-bugzilla CVE-2013-2191 SSL Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 60687 |
| Class: | Design Error |
| CVE: |
CVE-2013-2191 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2013 12:00AM |
| Updated: | Apr 13 2015 09:20PM |
| Credit: | Florian Weimer of the Red Hat |
| Vulnerable: |
S.u.S.E. openSUSE 12.3 S.u.S.E. openSUSE 12.2 S.u.S.E. openSUSE 11.4 Redhat python-bugzilla 0 |
| Not Vulnerable: |
Redhat python-bugzilla 0.9.0 |
Discussion
python-bugzilla CVE-2013-2191 SSL Certificate Validation Security Bypass Vulnerability
python-bugzilla is prone to a security-bypass vulnerability.
An attacker can exploit this issue to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
python-bugzilla versions prior to 0.9.0 are vulnerable.
python-bugzilla is prone to a security-bypass vulnerability.
An attacker can exploit this issue to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
python-bugzilla versions prior to 0.9.0 are vulnerable.
References
python-bugzilla CVE-2013-2191 SSL Certificate Validation Security Bypass Vulnerability
References:
References: