Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2013-2037
Description:httplib2 0.7.2, 0.8, and earlier, after an initial connection is made, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Test IDs: 1.3.6.1.4.1.25623.1.0.869542   1.3.6.1.4.1.25623.1.0.841551  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2013-2037
52179
http://www.securityfocus.com/bid/52179
USN-1948-1
http://www.ubuntu.com/usn/USN-1948-1
[oss-security] 20130501 Re: CVE Request: httplib2 ssl cert incorrect error handling
http://seclists.org/oss-sec/2013/q2/257
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=706602
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=706602
http://code.google.com/p/httplib2/issues/detail?id=282
http://code.google.com/p/httplib2/issues/detail?id=282
https://bugs.launchpad.net/httplib2/+bug/1175272
https://bugs.launchpad.net/httplib2/+bug/1175272




© 1998-2025 E-Soft Inc. All rights reserved.