Upstream information
Description
The verify_hostname_of_cert function in the certificate checking feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through 1.25 only matches the prefix of a hostname when no wildcard is used, which allows remote attackers to bypass the hostname check for a certificate.NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Novell/SUSE information
Novell Bugzilla entry: 535554 SUSE Security Advisories:- SUSE-SR:2009:015, published Tue, 15 Sep 2009 09:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|
