MGASA-2014-0257
Dashboard / Vulnerabilities / MGASA-2014-0257
Summary: Updated perl-LWP-Protocol-https package fixes CVE-2014-3230
Details: Updated perl-LWP-Protocol-https package fixes security vulnerability: It was reported that libwww-perl (LWP), when using IO::Socket::SSL (the default) and when the HTTPS_CA_DIR or HTTPS_CA_FILE environment variables were set, would disable server certificate verification, when the intent was to only disable hostname verification (CVE-2014-3230).
References: https://advisories.mageia.org/MGASA-2014-0257.html, https://lists.fedoraproject.org/pipermail/package-announce/2014-May/133535.html, https://bugs.mageia.org/show_bug.cgi?id=13425
Affected packages
Package
Name: perl-LWP-Protocol-https
Purl: pkg:rpm/mageia/perl-LWP-Protocol-https?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
