MGASA-2015-0165
Dashboard / Vulnerabilities / MGASA-2015-0165
Summary: Updated lftp packages fix CVE-2014-0139
Details: Updated lftp packages fix security vulnerability: lftp incorrectly validates wildcard SSL certificates containing literal IP addresses, so under certain conditions, it would allow and use a wildcard match specified in the CN field, allowing a malicious server to participate in a MITM attack or just fool users into believing that it is a legitimate site (CVE-2014-0139). lftp was affected by this issue as it uses code from cURL for checking SSL certificates. The curl package was fixed in MGASA-2014-0153.
References: https://advisories.mageia.org/MGASA-2015-0165.html, https://bugs.mageia.org/show_bug.cgi?id=15716, http://advisories.mageia.org/MGASA-2014-0153.html, http://lftp.yar.ru/news.html
Affected packages
Package
Name: lftp
Purl: pkg:rpm/mageia/lftp?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
