First published: Sun Nov 04 2012(Updated: )
The Canada Post (aka CanadaPost) module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Prestashop | ||
Presto-changeo |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5799 is classified as a medium severity vulnerability.
To fix CVE-2012-5799, ensure that the Canada Post module is updated to the latest version that implements proper SSL hostname verification.
CVE-2012-5799 can be exploited by man-in-the-middle attackers who can spoof SSL servers using valid certificates.
CVE-2012-5799 affects all versions of PrestaShop that include the vulnerable Canada Post module.
CVE-2012-5799 is not categorized as critical but poses risks to data security and integrity.