5.8
CVSSv2

CVE-2013-1909

Published: 23/08/2013 Updated: 15/07/2021
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

The Python client in Apache Qpid prior to 2.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle malicious users to spoof SSL servers via an arbitrary valid certificate.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise mrg 2.0

apache qpid 0.11

apache qpid 0.12

apache qpid 0.13

apache qpid 0.14

apache qpid 0.16

apache qpid 0.18

apache qpid

apache qpid 0.19

apache qpid 0.5

apache qpid 0.6

apache qpid 0.7

apache qpid 0.8

apache qpid 0.10

apache qpid 0.15

apache qpid 0.17

apache qpid 0.9

Vendor Advisories

Debian Bug report logs - #714133 python-qpid: CVE-2013-1909 Package: python-qpid; Maintainer for python-qpid is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Source for python-qpid is src:qpid-python (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Wed, 26 Jun 2013 05:45:02 UTC Severity: gra ...