It was discovered that there was a potential Man In the Middle (MITM) vulnerability in e2guardian, a web content filtering engine. Validation of SSL certificates was missing in e2guardian's own MITM . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3564-1
e2guardian did not validate TLS hostnames (CVE-2021-44273) References: - https://bugs.mageia.org/show_bug.cgi?id=29811 - https://www.openwall.com/lists/oss-security/2021/12/23/2 . MGASA-2021-0594 - Updated e2guardian packages fix security vulnerability Publication date: 30 Dec 2021 URL: https://advisories.mageia.org/MGASA-2021-0594.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-44273 e2guardian did not validate TLS hostnames (CVE-2021-44273) References: - https://bugs.mageia.org/show_bug.cgi?id=29811 - https://www.openwall.com/lists/oss-security/2021/12/23/2 - https://www.cve.org/CVERecord?id=CVE-2021-44273 SRPMS: - 8/core/e2guardian-5.3.4-1.1.mga8 . The recent e2guardian release addresses a critical TLS hostname validation vulnerability, bolstering the security of Mageia 8. For further details, refer to our advisory.. Mageia Security Update, e2guardian TLS Fix, Mageia Advisory 2021, Hostname Validation, Security Patch. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.