4
CVSSv2

CVE-2010-4334

Published: 14/01/2011 Updated: 14/10/2011
CVSS v2 Base Score: 4 | Impact Score: 4.9 | Exploitability Score: 4.9
VMScore: 356
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N

Vulnerability Summary

The IO::Socket::SSL module 1.35 for Perl, when verify_mode is not VERIFY_NONE, fails open to VERIFY_NONE instead of throwing an error when a ca_file/ca_path cannot be verified, which allows remote malicious users to bypass intended certificate restrictions.

Vulnerable Product Search on Vulmon Subscribe to Product

io-socket-ssl io-socket-ssl 1.35

Vendor Advisories

Debian Bug report logs - #606058 libio-socket-ssl-perl: IO::Socket::SSL ignores user request for peer verification Package: libio-socket-ssl-perl; Maintainer for libio-socket-ssl-perl is Debian Perl Group <pkg-perl-maintainers@listsaliothdebianorg>; Source for libio-socket-ssl-perl is src:libio-socket-ssl-perl (PTS, buildd, popco ...