CVE-2014-3230 Information

Description

The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl when using IO::Socket::SSL as the SSL socket class allows attackers to disable server certificate validation via the (1) HTTPS_CA_DIR or (2) HTTPS_CA_FILE environment variable.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Reference

http://www.openwall.com/lists/oss-security/2014/05/02/8 http://www.openwall.com/lists/oss-security/2014/05/04/1 http://www.openwall.com/lists/oss-security/2014/05/06/8 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=746579 https://github.com/libwww-perl/lwp-protocol-https/pull/14

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

NONE

Base Severity

5.9

Share on: