pyOpenSSL SSL Client Certificate Validation Security Bypass Vulnerability
BID:62258
Info
pyOpenSSL SSL Client Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 62258 |
| Class: | Design Error |
| CVE: |
CVE-2013-4314 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 06 2013 12:00AM |
| Updated: | Nov 13 2013 01:04AM |
| Credit: | Vincent Danen |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
pyOpenSSL SSL Client Certificate Validation Security Bypass Vulnerability
pyOpenSSL is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates from the server.
An attacker can exploit this issue to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
pyOpenSSL is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates from the server.
An attacker can exploit this issue to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Exploit / POC
pyOpenSSL SSL Client Certificate Validation Security Bypass Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
pyOpenSSL SSL Client Certificate Validation Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
pyOpenSSL SSL Client Certificate Validation Security Bypass Vulnerability
References:
References: