CVE-2009-3024
31.08.2009, 20:30
The verify_hostname_of_cert function in the certificate checking feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through 1.25 only matches the prefix of a hostname when no wildcard is used, which allows remote attackers to bypass the hostname check for a certificate.Enginsight
Vendor | Product | Version |
---|---|---|
io-socket-ssl | io-socket-ssl | 1.14 |
io-socket-ssl | io-socket-ssl | 1.15 |
io-socket-ssl | io-socket-ssl | 1.16 |
io-socket-ssl | io-socket-ssl | 1.16_1:_1 |
io-socket-ssl | io-socket-ssl | 1.16_2:_2 |
io-socket-ssl | io-socket-ssl | 1.16_3:_3 |
io-socket-ssl | io-socket-ssl | 1.17 |
io-socket-ssl | io-socket-ssl | 1.18 |
io-socket-ssl | io-socket-ssl | 1.19 |
io-socket-ssl | io-socket-ssl | 1.20 |
io-socket-ssl | io-socket-ssl | 1.21 |
io-socket-ssl | io-socket-ssl | 1.22 |
io-socket-ssl | io-socket-ssl | 1.23 |
io-socket-ssl | io-socket-ssl | 1.24 |
io-socket-ssl | io-socket-ssl | 1.25 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References