CVE-2010-4334
14.01.2011, 01:00
The IO::Socket::SSL module 1.35 for Perl, when verify_mode is not VERIFY_NONE, fails open to VERIFY_NONE instead of throwing an error when a ca_file/ca_path cannot be verified, which allows remote attackers to bypass intended certificate restrictions.Enginsight
Vendor | Product | Version |
---|---|---|
io-socket-ssl | io-socket-ssl | 1.35 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References