Hostname Matching Flaw in IO-Socket-SSL Versions 1.14-1.25
CVE-2009-3024

Currently unrated

Key Information:

Vendor
CVE Published:
31 August 2009

What is CVE-2009-3024?

The 'verify_hostname_of_cert' function in IO-Socket-SSL versions 1.14 to 1.25 allows for the hostname check of a certificate to be bypassed by matching only the prefix of the hostname unless a wildcard is employed. This behavior can be exploited by remote attackers to present a different hostname for a given SSL certificate, potentially compromising the security of the connection.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.