Summary
The IO::Socket::SSL module for Perl is prone to a security- bypass vulnerability because the application fails to properly validate certificate hostnames.
Successfully exploiting this issue allows attackers to bypass certain security restrictions, which may aid in further attacks.
Versions prior to IO::Socket::SSL 1.26 are vulnerable.
Solution
Updates are available. Please see the references for more information.
References
Updated on 2017-03-28
Severity
Classification
-
CVE CVE-2009-3024 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities
- Apache Traffic Server Remote DNS Cache Poisoning Vulnerability
- Apple Safari WebKit Information Disclosure Vulnerability (Mac OS X)
- Apple Safari 'javascript: URI' XSS Vulnerability - Sep09
- Adobe Flash Player Unspecified Cross-Site Scripting Vulnerability June-2011 (Linux)
- Adobe Reader Cross-Site Scripting & Denial of Service Vulnerabilities (Linux)