Lucene search

K
mageiaGentoo FoundationMGASA-2014-0551
HistoryDec 26, 2014 - 8:04 p.m.

Updated not-yet-commons-ssl packages fix CVE-2014-3604

2014-12-2620:04:58
Gentoo Foundation
advisories.mageia.org
15

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.001

Percentile

42.3%

Updated not-yet-commons-ssl packages fixes security vulnerability: It was discovered that the implementation used by the Not Yet Commons SSL project to check that the server hostname matches the domain name in the subject’s CN field was flawed. This can be exploited by a Man-in-the-middle (MITM) attack, where the attacker can spoof a valid certificate using a specially crafted subject (CVE-2014-3604).

OSVersionArchitecturePackageVersionFilename
Mageia4noarchnot-yet-commons-ssl< 0.3.15-1not-yet-commons-ssl-0.3.15-1.mga4

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.001

Percentile

42.3%