CVE-2011-0633

UnknownEPSS 4.25%

Last modified

CVE-2011-0633 is a vulnerability of currently unknown severity. The Net::HTTPS module in libwww-perl (LWP) before 6.00, as used in WWW::Mechanize, LWP::UserAgent, and other products, when running in environments that do not set the If-SSL-Cert-Subject header, does not enable full validation of SSL certificates by default, which allows remote attackers to spoof servers via man-in-the-middle (MITM) attacks involving hostnames that are not properly validated. NOTE: it could be argued that this is a design limitation of the Net::HTTPS API, and separate implementations should be independently assigned CVE identifiers for not working around this limitation. EPSS estimates a 4.25% chance of exploitation in the next 30 days.

Description

The Net::HTTPS module in libwww-perl (LWP) before 6.00, as used in WWW::Mechanize, LWP::UserAgent, and other products, when running in environments that do not set the If-SSL-Cert-Subject header, does not enable full validation of SSL certificates by default, which allows remote attackers to spoof servers via man-in-the-middle (MITM) attacks involving hostnames that are not properly validated. NOTE: it could be argued that this is a design limitation of the Net::HTTPS API, and separate implementations should be independently assigned CVE identifiers for not working around this limitation. However, because this API was modified within LWP, a single CVE identifier has been assigned.

Metrics

EPSS Probability
4.25%

89.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Gisle AasLibwww-Perl0.01
Gisle AasLibwww-Perl0.02
Gisle AasLibwww-Perl0.03
Gisle AasLibwww-Perl0.04
Gisle AasLibwww-Perl5.00
Gisle AasLibwww-Perl5.01
Gisle AasLibwww-Perl5.02
Gisle AasLibwww-Perl5.03
Gisle AasLibwww-Perl5.04
Gisle AasLibwww-Perl5.05
Gisle AasLibwww-Perl5.06
Gisle AasLibwww-Perl5.07
Gisle AasLibwww-Perl5.08
Gisle AasLibwww-Perl5.09
Gisle AasLibwww-Perl5.10
Gisle AasLibwww-Perl5.11
Gisle AasLibwww-Perl5.12
Gisle AasLibwww-Perl5.13
Gisle AasLibwww-Perl5.14
Gisle AasLibwww-Perl5.15
Gisle AasLibwww-Perl5.16
Gisle AasLibwww-Perl5.17
Gisle AasLibwww-Perl5.18
Gisle AasLibwww-Perl5.18_03
Gisle AasLibwww-Perl5.18_04
Gisle AasLibwww-Perl5.18_05
Gisle AasLibwww-Perl5.19
Gisle AasLibwww-Perl5.20
Gisle AasLibwww-Perl5.21
Gisle AasLibwww-Perl5.22
Gisle AasLibwww-Perl5.30
Gisle AasLibwww-Perl5.31
Gisle AasLibwww-Perl5.32
Gisle AasLibwww-Perl5.33
Gisle AasLibwww-Perl5.34
Gisle AasLibwww-Perl5.35
Gisle AasLibwww-Perl5.36
Gisle AasLibwww-Perl5.41
Gisle AasLibwww-Perl5.42
Gisle AasLibwww-Perl5.43
Gisle AasLibwww-Perl5.44
Gisle AasLibwww-Perl5.45
Gisle AasLibwww-Perl5.46
Gisle AasLibwww-Perl5.47
Gisle AasLibwww-Perl5.48
Gisle AasLibwww-Perl5.49
Gisle AasLibwww-Perl5.50
Gisle AasLibwww-Perl5.51
Gisle AasLibwww-Perl5.52
Gisle AasLibwww-Perl5.53

Showing 50 of 124 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2011-0633?
The Net::HTTPS module in libwww-perl (LWP) before 6.00, as used in WWW::Mechanize, LWP::UserAgent, and other products, when running in environments that do not set the If-SSL-Cert-Subject header, does not enable full validation of SSL certificates by default, which allows remote attackers to spoof servers via man-in-the-middle (MITM) attacks involving hostnames that are not properly validated. NOTE: it could be argued that this is a design limitation of the Net::HTTPS API, and separate implementations should be independently assigned CVE identifiers for not working around this limitation. However, because this API was modified within LWP, a single CVE identifier has been assigned.
How severe is CVE-2011-0633?
Severity scoring for CVE-2011-0633 is pending analysis. The EPSS model estimates a 4.25% probability of exploitation in the next 30 days.
How do I fix CVE-2011-0633?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2011-0633?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST