Bugzilla – Bug 876862
VUL-0: CVE-2014-3230: perl-LWP-Protocol-https: Environment variables HTTPS_CA_DIR or HTTPS_CA_FILE disable hostname verification
Last modified: 2019-07-08 14:25:31 UTC
Reported by Kurt Seifried on oss-security (Message-ID: <53640609.10003@redhat.com>) Setting the environment variables HTTPS_CA_DIR or HTTPS_CA_FILE disable hostname verification. So every valid certificate is accepted, regardless of the CN. Patch is available in https://github.com/libwww-perl/lwp-protocol-https/pull/14 References: http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-3230.html
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (876862) was mentioned in https://build.opensuse.org/request/show/234143 13.1+12.3 / perl-LWP-Protocol-https
This is an autogenerated message for OBS integration: This bug (876862) was mentioned in https://build.opensuse.org/request/show/234175 Factory / perl-LWP-Protocol-https
openSUSE-SU-2014:0710-1: An update that fixes one vulnerability is now available. Category: security (low) Bug References: 876862 CVE References: CVE-2014-3230 Sources used: openSUSE 13.1 (src): perl-LWP-Protocol-https-6.04-2.4.1 openSUSE 12.3 (src): perl-LWP-Protocol-https-6.03-4.4.1
openSUSE released and SLE12 fixed