Back to search
CVE-2014-0363
Published: Apr 30, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://issues.igniterealtime.org/browse/SMACK-410
x_refsource_CONFIRM
59291
third-party-advisory
x_refsource_SECUNIA
59290
third-party-advisory
x_refsource_SECUNIA
RHSA-2015:1176
vendor-advisory
x_refsource_REDHAT
VU#489228
third-party-advisory
x_refsource_CERT-VN
67119
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now