CVE-2011-4092: Input Validation

Published Nov 1, 2011
·
Updated

obby (aka libobby) does not verify SSL server certificates, which allows remote attackers to spoof servers via an arbitrary certificate.

Other sources

Vasiliy Kulikov reported [1] that obby does not check a server's SSL certificate when connecting. It also sends the password in plaintext form over the SSL channel. An attacker able to perform a MITM attack on the connection could easily do so without discovery due to obby not checking the server's SSL certificate.

Note: if the client is Gobby, the reconnection attempt will require user interaction.

Upstream has indicated [2] that it is not worth the effort to implement SSL certificate checking in obby as it is deprecated by libinfinity, which is used by the development version of Gobby, so there is currently no fix for obby.

[1] http://www.openwall.com/lists/oss-security/2011/10/30/3 [2] http://www.openwall.com/lists/oss-security/2011/10/30/5

Red Hat

Affected Software

1 affected component
Ubuntu Developers Obby

Event History

Nov 1, 2011
Data Sourced
08:33 PM
DescriptionSeverityAffected Software
Feb 10, 2014
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2011-4092?

CVE-2011-4092 is considered a critical vulnerability due to its potential for server spoofing and plaintext credential transmission.

2

How do I fix CVE-2011-4092?

To fix CVE-2011-4092, ensure that your version of Obby is updated to a version that implements SSL certificate verification.

3

What are the consequences of CVE-2011-4092?

The main consequence of CVE-2011-4092 is that an attacker could impersonate a legitimate server and intercept sensitive information transmitted by users.

4

Which versions of Obby are affected by CVE-2011-4092?

CVE-2011-4092 affects all versions of Obby prior to the implementation of SSL certificate verification.

5

Is there any workaround for CVE-2011-4092 if I cannot update immediately?

As a workaround for CVE-2011-4092, consider using a VPN or other secure communication method to protect data while you arrange for updates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203