CVE-2013-6444
Publication date 5 May 2014
Last updated 24 July 2024
Ubuntu priority
Description
PyWBEM 0.7 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| pywbem | ||
| 18.04 LTS bionic |
Fixed 0.8.0~dev650-1
|
|
| 16.04 LTS xenial |
Fixed 0.8.0~dev650-1
|
|
| 14.04 LTS trusty |
Fixed 0.7.0-4ubuntu1~14.04.1
|
|