CVE-2013-0289: Medium severity Isync Project Isync vulnerability
Published May 23, 2014
·Updated
Isync 0.4 before 1.0.6, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Affected Software
11 affected components
Isync Project Isync=0.4
Isync Project Isync=0.5
Isync Project Isync=0.6
Isync Project Isync=0.7
Isync Project Isync=0.8
Isync Project Isync=1.0.0
Isync Project Isync=1.0.1
Isync Project Isync=1.0.2
Isync Project Isync=1.0.3
Isync Project Isync=1.0.4
Isync Project Isync=1.0.5
Remediation
Patch Available
Event History
May 23, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-0289?
CVE-2013-0289 has been classified as a moderate severity vulnerability due to its potential for man-in-the-middle attacks.
2
How do I fix CVE-2013-0289?
To fix CVE-2013-0289, upgrade to isync version 1.0.6 or later, which includes the required hostname verification.
3
What types of attacks can exploit CVE-2013-0289?
CVE-2013-0289 can be exploited by man-in-the-middle attackers spoofing SSL servers.
4
Which versions of isync are affected by CVE-2013-0289?
CVE-2013-0289 affects isync versions 0.4 to 1.0.5.
5
Is CVE-2013-0289 related to SSL certificates?
Yes, CVE-2013-0289 is related to the lack of verification of SSL server certificates, enabling possible spoofing.