The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl, when using IO::Socket::SSL as the SSL socket class, allows attackers to disable server certificate validation via the (1) HTTPS_CA_DIR or (2) HTTPS_CA_FILE environment variable.
References:CPANSA-LWP-Protocol-https-2014-3230
The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl, when using IO::Socket::SSL as the SSL socket class, allows attackers to disable server certificate validation via the (1) HTTPS_CA_DIR or (2) HTTPS_CA_FILE environment variable.
| Affected Packages | Affected Versions | Fixed Versions | |
|---|---|---|---|
| cpan:LWP-Protocol-https | >= 6.04, <= 6.06 | 6.06 | |
Affected Version RangesAll affected versionsAll unaffected versions |
|||