CVE-2011-5239: Input Validation
Published Nov 6, 2012
·Updated
CiviCRM 4.0.5 and 4.1.1 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Affected Software
2 affected components
CiviCRM CiviCRM=4.1.1
CiviCRM CiviCRM=4.0.5
Event History
Nov 6, 2012
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-5239?
CVE-2011-5239 has a medium severity rating due to its potential impact on SSL certificate validation.
2
How do I fix CVE-2011-5239?
To fix CVE-2011-5239, upgrade CiviCRM to version 4.1.2 or later, which includes the necessary security updates.
3
What systems are affected by CVE-2011-5239?
CVE-2011-5239 affects CiviCRM versions 4.0.5 and 4.1.1.
4
What type of attack does CVE-2011-5239 allow?
CVE-2011-5239 allows man-in-the-middle attackers to spoof SSL servers using valid certificates.
5
Is there a workaround for CVE-2011-5239?
There is no specific workaround for CVE-2011-5239; updating to the latest version is recommended.