Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Ubuntu 14.04 LTS USN-2292-1 Moderate: LWP Protocol HTTPS Data Exposure

ubuntu
Calendar Grey July 17, 2014
Scroller Ubuntu
=========================================================================Ubuntu Security Notice USN-
LWP::Protocol::https could be made to expose sensitive information over the network.

Summary

LWP::Protocol::https could be made to expose sensitive information over the

network.

Software Description:

- liblwp-protocol-https-perl: HTTPS driver for LWP::UserAgent

Details:

It was discovered that the LWP::Protocol::https perl module incorrectly

disabled peer certificate verification completely when only hostname

verification was requested to be disabled. If a remote attacker were able

to perform a man-in-the-middle attack, this flaw could possibly be

exploited in certain scenarios to alter or compromise confidential

information in applications that used the LWP::Protocol::https module.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
  liblwp-protocol-https-perl      6.04-2ubuntu0.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2292-1

CVE-2014-3230

July 17, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.