First published: Sun Nov 04 2012(Updated: )
The Authorize.Net module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Irata Authorize.net Module | ||
Ubercart Ubercart |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5803 is considered a medium severity vulnerability due to its potential for man-in-the-middle attacks.
To fix CVE-2012-5803, ensure that the Authorize.Net module is updated to the latest version where the hostname verification issue is addressed.
CVE-2012-5803 affects the Irata Authorize.Net module and the Ubercart platform.
Yes, exploitation of CVE-2012-5803 can allow attackers to spoof SSL servers, potentially leading to data breaches.
CVE-2012-5803 undermines SSL security by allowing man-in-the-middle attacks due to improper hostname verification.