CVE-2012-5662
27.05.2014, 14:55
x3270 before 3.3.12ga12 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.Enginsight
Vendor | Product | Version |
---|---|---|
paul_mattes | x3270 | 𝑥 ≤ 3.3.12 |
paul_mattes | x3270 | 3.3.5 |
paul_mattes | x3270 | 3.3.6 |
paul_mattes | x3270 | 3.3.7 |
paul_mattes | x3270 | 3.3.8 |
paul_mattes | x3270 | 3.3.8:p1 |
paul_mattes | x3270 | 3.3.8:p2 |
paul_mattes | x3270 | 3.3.8:p3 |
paul_mattes | x3270 | 3.3.9:ga11 |
paul_mattes | x3270 | 3.3.9:ga12 |
paul_mattes | x3270 | 3.3.10:ga3 |
paul_mattes | x3270 | 3.3.10:ga4 |
paul_mattes | x3270 | 3.3.10:ga5 |
paul_mattes | x3270 | 3.3.11:beta2 |
paul_mattes | x3270 | 3.3.11:beta4 |
paul_mattes | x3270 | 3.3.11:ga6 |
paul_mattes | x3270 | 3.3.12:beta6 |
paul_mattes | x3270 | 3.3.12:ga10 |
paul_mattes | x3270 | 3.3.12:ga7 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ibm-3270 |
|
Common Weakness Enumeration
References