Apache Qpid Python Client SSL Certificate Verification Information Disclosure Vulnerability
BID:60800
Info
Apache Qpid Python Client SSL Certificate Verification Information Disclosure Vulnerability
| Bugtraq ID: | 60800 |
| Class: | Design Error |
| CVE: |
CVE-2013-1909 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2013 12:00AM |
| Updated: | Jun 12 2013 12:00AM |
| Credit: | Ken Giusti of Red Hat |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Apache Qpid Python Client SSL Certificate Verification Information Disclosure Vulnerability
Apache QPID is prone to an information-disclosure vulnerability because it fails to properly verify SSL certificates from a server.
An attacker can exploit this issue through man-in-the-middle attacks by impersonating a trusted server. This may allow the attacker to obtain or modify sensitive information. Information harvested may aid in further attacks.
Apache QPID 0.20 is vulnerable; other versions may also be affected.
Apache QPID is prone to an information-disclosure vulnerability because it fails to properly verify SSL certificates from a server.
An attacker can exploit this issue through man-in-the-middle attacks by impersonating a trusted server. This may allow the attacker to obtain or modify sensitive information. Information harvested may aid in further attacks.
Apache QPID 0.20 is vulnerable; other versions may also be affected.
Exploit / POC
Apache Qpid Python Client SSL Certificate Verification Information Disclosure Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.