[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2014-397 ---- libserf

ID: oval:org.secpod.oval:def:1600031Date: (C)2016-01-19   (M)2023-11-10
Class: PATCHFamily: unix




The serf_ssl_cert_issuer, serf_ssl_cert_subject, and serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in the subject"s Common Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

Platform:
Amazon Linux AMI
Product:
libserf
Reference:
ALAS-2014-397
CVE-2014-3504
CVE    1
CVE-2014-3504
CPE    2
cpe:/a:apache:libserf
cpe:/o:amazon:linux

© SecPod Technologies