{ "id": "CVE-2009-3024", "sourceIdentifier": "cve@mitre.org", "published": "2009-08-31T20:30:01.093", "lastModified": "2011-01-20T06:35:32.120", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "The verify_hostname_of_cert function in the certificate checking feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through 1.25 only matches the prefix of a hostname when no wildcard is used, which allows remote attackers to bypass the hostname check for a certificate." }, { "lang": "es", "value": "La funci\u00f3n verify_hostname_of_cert en la funcionalidad de verificaci\u00f3n de certificado en IO-Socket-SSL (IO::Socket::SSL) v1.14 a la v1.25 \u00fanicamente compara el prefijo de un hostname cuando no se usa un comod\u00edn, lo que permite a atacantes remotos evitar la validaci\u00f3n de un hostname para un certificado." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "NONE", "baseScore": 4.3 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-310" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:io-socket-ssl:io-socket-ssl:1.14:*:*:*:*:*:*:*", "matchCriteriaId": "80EEE704-744B-487E-89D0-C38F0F0F00D1" }, { "vulnerable": true, "criteria": "cpe:2.3:a:io-socket-ssl:io-socket-ssl:1.15:*:*:*:*:*:*:*", "matchCriteriaId": "50AF3CCC-A126-40C2-BDE8-A376F286A5FE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:io-socket-ssl:io-socket-ssl:1.16:*:*:*:*:*:*:*", "matchCriteriaId": "E7922D38-6AD7-4D81-AF30-623BB8234E69" }, { "vulnerable": true, "criteria": "cpe:2.3:a:io-socket-ssl:io-socket-ssl:1.16_1:*:*:*:*:*:*:*", "matchCriteriaId": "760ED2EB-9255-49A4-AFE7-4DD960215BD8" }, { "vulnerable": true, "criteria": "cpe:2.3:a:io-socket-ssl:io-socket-ssl:1.16_2:*:*:*:*:*:*:*", "matchCriteriaId": "7131102E-BEDB-4D63-9005-0EB646CAA918" }, { "vulnerable": true, "criteria": "cpe:2.3:a:io-socket-ssl:io-socket-ssl:1.16_3:*:*:*:*:*:*:*", "matchCriteriaId": "064EBF4B-37EF-4334-87B4-EC4407A4F621" }, { "vulnerable": true, "criteria": "cpe:2.3:a:io-socket-ssl:io-socket-ssl:1.17:*:*:*:*:*:*:*", "matchCriteriaId": "288417CD-C82F-48DE-9D9F-897E3A6EB833" }, { "vulnerable": true, "criteria": "cpe:2.3:a:io-socket-ssl:io-socket-ssl:1.18:*:*:*:*:*:*:*", "matchCriteriaId": "2BEE69A2-16BF-4E7B-9985-BFDFA5354DB9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:io-socket-ssl:io-socket-ssl:1.19:*:*:*:*:*:*:*", "matchCriteriaId": "9AED6875-A544-4608-9277-E82C5977D9EB" }, { "vulnerable": true, "criteria": "cpe:2.3:a:io-socket-ssl:io-socket-ssl:1.20:*:*:*:*:*:*:*", "matchCriteriaId": "669BA841-F8D7-4E4D-B9B5-776248A7C9D9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:io-socket-ssl:io-socket-ssl:1.21:*:*:*:*:*:*:*", "matchCriteriaId": "7FA78DEB-D81F-4442-ABF1-37FD5226EC12" }, { "vulnerable": true, "criteria": "cpe:2.3:a:io-socket-ssl:io-socket-ssl:1.22:*:*:*:*:*:*:*", "matchCriteriaId": "58BAC664-C570-4F8F-9CAB-8DEF9A3D54CD" }, { "vulnerable": true, "criteria": "cpe:2.3:a:io-socket-ssl:io-socket-ssl:1.23:*:*:*:*:*:*:*", "matchCriteriaId": "82C2F301-5CD4-4729-BC62-16B60E0EC9BA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:io-socket-ssl:io-socket-ssl:1.24:*:*:*:*:*:*:*", "matchCriteriaId": "75C353EA-2FCC-4B0C-A4E7-CD8E0AC89255" }, { "vulnerable": true, "criteria": "cpe:2.3:a:io-socket-ssl:io-socket-ssl:1.25:*:*:*:*:*:*:*", "matchCriteriaId": "8E6CA710-EC56-46A1-9114-48E928DFFB6D" } ] } ] } ], "references": [ { "url": "http://cpansearch.perl.org/src/SULLR/IO-Socket-SSL-1.30/Changes", "source": "cve@mitre.org" }, { "url": "http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html", "source": "cve@mitre.org" }, { "url": "http://www.gentoo.org/security/en/glsa/glsa-201101-06.xml", "source": "cve@mitre.org" }, { "url": "http://www.openwall.com/lists/oss-security/2009/08/28/1", "source": "cve@mitre.org" }, { "url": "http://www.openwall.com/lists/oss-security/2009/08/29/1", "source": "cve@mitre.org" }, { "url": "http://www.openwall.com/lists/oss-security/2009/08/31/4", "source": "cve@mitre.org" }, { "url": "http://www.vupen.com/english/advisories/2011/0118", "source": "cve@mitre.org" } ] }