Ubuntu Security Notice (C) 2014-2015 Canonical, Inc. / NASL script (C) 2014-2015 Tenable Network Security, Inc.
The remote Ubuntu host is missing a security-related patch.
It was discovered that the LWP::Protocol::https perl module
incorrectly disabled peer certificate verification completely when
only hostname verification was requested to be disabled. If a remote
attacker were able to perform a man-in-the-middle attack, this flaw
could possibly be exploited in certain scenarios to alter or
compromise confidential information in applications that used the
Update the affected liblwp-protocol-https-perl package.
Risk factor :
Medium / CVSS Base Score : 6.4
CVSS Temporal Score : 5.6
Public Exploit Available : true