The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl, when using IO::Socket::SSL as the SSL socket class, allows attackers to disable server certificate validation via the (1) HTTPS_CA_DIR or (2) HTTPS_CA_FILE environment variable.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-3246 | The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl, when using IO::Socket::SSL as the SSL socket class, allows attackers to disable server certificate validation via the (1) HTTPS_CA_DIR or (2) HTTPS_CA_FILE environment variable. |
Ubuntu USN |
USN-2292-1 | LWP::Protocol::https vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T10:35:57.043Z
Reserved: 2014-05-06T00:00:00
Link: CVE-2014-3230
No data.
Status : Modified
Published: 2020-01-28T16:15:12.277
Modified: 2024-11-21T02:07:43.337
Link: CVE-2014-3230
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN