RUSTSEC-2016-0001
Dashboard / Vulnerabilities / RUSTSEC-2016-0001
Summary: SSL/TLS MitM vulnerability due to insecure defaults
Details: All versions of rust-openssl prior to 0.9.0 contained numerous insecure defaults including off-by-default certificate verification and no API to perform hostname verification. Unless configured correctly by a developer, these defaults could allow an attacker to perform man-in-the-middle attacks. The problem was addressed in newer versions by enabling certificate verification by default and exposing APIs to perform hostname verification. Use the `SslConnector` and `SslAcceptor` types to take advantage of these new features (as opposed to the lower-level `SslContext` type).
References: https://crates.io/crates/openssl, https://rustsec.org/advisories/RUSTSEC-2016-0001.html, https://github.com/sfackler/rust-openssl/releases/tag/v0.9.0
Affected packages
Package
Name: openssl
Purl: pkg:cargo/openssl
Affected ranges
Type: SEMVER
Events:
