ID | CVE-2013-2037 | ||||||
Sažetak | httplib2 0.7.2, 0.8, and earlier, after an initial connection is made, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | ||||||
Reference | |||||||
CVSS |
|
||||||
Pristup |
|
||||||
Impact |
|
||||||
CVSS vektor | AV:N/AC:H/Au:N/C:N/I:P/A:N | ||||||
Zadnje važnije ažuriranje | 06-12-2018 - 20:53 | ||||||
Objavljeno | 18-01-2014 - 21:55 |