Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 386301 - dev-python/libcloud: certificate verification failure (CVE-2010-4340)
Summary: dev-python/libcloud: certificate verification failure (CVE-2010-4340)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-10-08 13:46 UTC by GLSAMaker/CVETool Bot
Modified: 2011-10-08 13:47 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2011-10-08 13:46:59 UTC
CVE-2010-4340 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4340):
  libcloud before 0.4.1 does not verify SSL certificates for HTTPS
  connections, which allows remote attackers to spoof certificates and bypass
  intended access restrictions via a man-in-the-middle (MITM) attack.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2011-10-08 13:47:42 UTC
Already fixed. Closing noglsa.