Cyberduck CVE-2014-2845 X.509 Certificate Validation Security Bypass Vulnerability
BID:67243
Info
Cyberduck CVE-2014-2845 X.509 Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 67243 |
| Class: | Design Error |
| CVE: |
CVE-2014-2845 |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2014 12:00AM |
| Updated: | May 06 2014 12:00AM |
| Credit: | Micha Borrmann of the SySS GmbH |
| Vulnerable: |
Cyberduck Cyberduck 4.4.3 for Windows |
| Not Vulnerable: |
Cyberduck Cyberduck 4.4.4 |
Exploit / POC
Cyberduck CVE-2014-2845 X.509 Certificate Validation Security Bypass Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
References
Cyberduck CVE-2014-2845 X.509 Certificate Validation Security Bypass Vulnerability
References:
References:
- Cyberduck Homepage (Cyberduck)
- Cyberduck Release Notes (Cyberduck)