PublicDateAtUSN: 2014-05-07
Candidate: CVE-2014-3230
PublicDate: 2020-01-28 16:15:00 UTC
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3230
 https://ubuntu.com/security/notices/USN-2292-1
Description:
 The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl,
 when using IO::Socket::SSL as the SSL socket class, allows attackers to
 disable server certificate validation via the (1) HTTPS_CA_DIR or (2)
 HTTPS_CA_FILE environment variable.
Ubuntu-Description:
Notes:
 jdstrand> per Debian, introduced by https://github.com/dagolden/lwp-protocol-https/commit/bcc46ce2dab53d2e2baa583f2243d6fc7d36dcc8
 jdstrand> fix for https://rt.cpan.org/Public/Bug/Display.html?id=81948
  introduced the bug (6.04)
 mdeslaur> as of 2014-06-27, proposed patch is still being discussed
Bugs:
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=746579
Priority: medium
Discovered-by:
Assigned-to: mdeslaur
CVSS:
 nvd: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N [5.9 MEDIUM]

Patches_liblwp-protocol-https-perl:
 vendor: https://github.com/libwww-perl/lwp-protocol-https/pull/14
upstream_liblwp-protocol-https-perl: released (6.04-3)
lucid_liblwp-protocol-https-perl: DNE
precise_liblwp-protocol-https-perl: not-affected
quantal_liblwp-protocol-https-perl: not-affected (6.03-1)
saucy_liblwp-protocol-https-perl: ignored (reached end-of-life)
trusty_liblwp-protocol-https-perl: released (6.04-2ubuntu0.1)
trusty/esm_liblwp-protocol-https-perl: released (6.04-2ubuntu0.1)
devel_liblwp-protocol-https-perl: not-affected (6.04-3)
