CVE-2009-3024
31.08.2009, 20:30
The verify_hostname_of_cert function in the certificate checking feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through 1.25 only matches the prefix of a hostname when no wildcard is used, which allows remote attackers to bypass the hostname check for a certificate.Enginsight
| Vendor | Product | Version |
|---|---|---|
| io-socket-ssl | io-socket-ssl | 1.14 |
| io-socket-ssl | io-socket-ssl | 1.15 |
| io-socket-ssl | io-socket-ssl | 1.16 |
| io-socket-ssl | io-socket-ssl | 1.16_1:_1 |
| io-socket-ssl | io-socket-ssl | 1.16_2:_2 |
| io-socket-ssl | io-socket-ssl | 1.16_3:_3 |
| io-socket-ssl | io-socket-ssl | 1.17 |
| io-socket-ssl | io-socket-ssl | 1.18 |
| io-socket-ssl | io-socket-ssl | 1.19 |
| io-socket-ssl | io-socket-ssl | 1.20 |
| io-socket-ssl | io-socket-ssl | 1.21 |
| io-socket-ssl | io-socket-ssl | 1.22 |
| io-socket-ssl | io-socket-ssl | 1.23 |
| io-socket-ssl | io-socket-ssl | 1.24 |
| io-socket-ssl | io-socket-ssl | 1.25 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References