MGASA-2014-0551
Dashboard / Vulnerabilities / MGASA-2014-0551
Summary: Updated not-yet-commons-ssl packages fix CVE-2014-3604
Details: Updated not-yet-commons-ssl packages fixes security vulnerability: It was discovered that the implementation used by the Not Yet Commons SSL project to check that the server hostname matches the domain name in the subject's CN field was flawed. This can be exploited by a Man-in-the-middle (MITM) attack, where the attacker can spoof a valid certificate using a specially crafted subject (CVE-2014-3604).
References: https://advisories.mageia.org/MGASA-2014-0551.html, https://bugs.mageia.org/show_bug.cgi?id=14175, https://lists.fedoraproject.org/pipermail/package-announce/2014-September/138550.html
Affected packages
Package
Name: not-yet-commons-ssl
Purl: pkg:rpm/mageia/not-yet-commons-ssl?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
