Mandriva Linux Security Advisory : perl-IO-Socket-SSL (MDVSA-2009:252-1)
Medium Nessus Plugin ID 41960
SynopsisThe remote Mandriva Linux host is missing a security update.
DescriptionA vulnerability was discovered and corrected in perl-IO-Socket-SSL :
The verify_hostname_of_cert function in the certificate checking feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through 1.25 only matches the prefix of a hostname when no wildcard is used, which allows remote attackers to bypass the hostname check for a certificate (CVE-2009-3024).
This update provides a fix for this vulnerability.
Packages were missing for 2009.0, this update addresses the problem.
SolutionUpdate the affected perl-IO-Socket-SSL package.