Hostname Matching Flaw in IO-Socket-SSL Versions 1.14-1.25
CVE-2009-3024
Currently unrated
What is CVE-2009-3024?
The 'verify_hostname_of_cert' function in IO-Socket-SSL versions 1.14 to 1.25 allows for the hostname check of a certificate to be bypassed by matching only the prefix of the hostname unless a wildcard is employed. This behavior can be exploited by remote attackers to present a different hostname for a given SSL certificate, potentially compromising the security of the connection.
