Mandriva Linux Security Advisory 2015-213

Discussion in 'News Aggregator' started by Packet Storm, 30 Apr 2015.

  1. Packet Storm

    Packet Storm Guest

    Mandriva Linux Security Advisory 2015-213 - lftp incorrectly validates wildcard SSL certificates containing literal IP addresses, so under certain conditions, it would allow and use a wildcard match specified in the CN field, allowing a malicious server to participate in a MITM attack or just fool users into believing that it is a legitimate site. lftp was affected by this issue as it uses code from cURL for checking SSL certificates. The curl package was fixed in MDVSA-2015:098.

    Continue reading...
     

Share This Page

Loading...