Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-2132

Опубликовано: 23 апр. 2012
Источник: redhat
CVSS2: 5.8
EPSS Низкий

Описание

libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection.

Отчет

Not vulnerable. This issue did not affect the versions of libsoup as shipped with Red Hat Enterprise Linux 5 and 6, as they do not include support for the SOUP_MESSAGE_CERTIFICATE_TRUSTED feature.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libsoupNot affected
Red Hat Enterprise Linux 6libsoupNot affected

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=817692libsoup: does not indicate whether or not an SSL certificate is valid

EPSS

Процентиль: 73%
0.01553
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 14 лет назад

libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection.

nvd
почти 14 лет назад

libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection.

debian
почти 14 лет назад

libsoup 2.32.2 and earlier does not validate certificates or clear the ...

github
около 4 лет назад

libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection.

EPSS

Процентиль: 73%
0.01553
Низкий

5.8 Medium

CVSS2