Summary
The IO::Socket::SSL module for Perl is prone to a security- bypass vulnerability because the application fails to properly validate certificate hostnames.
Successfully exploiting this issue allows attackers to bypass certain security restrictions, which may aid in further attacks.
Versions prior to IO::Socket::SSL 1.26 are vulnerable.
Solution
Updates are available. Please see the references for more information.
References
Updated on 2017-03-28
Severity
Classification
-
CVE CVE-2009-3024 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities
- Adobe Digital Edition Information Disclosure Vulnerability (Mac OS X)
- Apple Safari Secure Cookie Security Bypass Vulnerability (Mac OS X)
- Apache Tomcat Multiple Vulnerabilities - 01 Mar14
- Adobe Reader Multiple Unspecified Vulnerabilities Jun06 (Windows)
- Apache Tomcat XML External Entity Information Disclosure Vulnerability