CVE-2016-10932: Medium severity hyper hyper vulnerability
Published Aug 26, 2019
·Updated
An issue was discovered in the hyper crate before 0.9.4 for Rust on Windows. There is an HTTPS man-in-the-middle vulnerability because hostname verification was omitted.
Affected Software
2 affected components
hyper hyper<0.9.4
Microsoft Windows
Event History
Aug 26, 2019
CVE Published
via MITRE·12:01 PM
Data Sourced
via MITRE·12:01 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10932?
CVE-2016-10932 is classified as a high-severity vulnerability due to its potential for man-in-the-middle attacks.
2
How do I fix CVE-2016-10932?
To mitigate CVE-2016-10932, update the hyper crate to version 0.9.4 or later.
3
What systems are affected by CVE-2016-10932?
CVE-2016-10932 specifically affects the hyper crate versions prior to 0.9.4 on Windows.
4
What kind of vulnerability is CVE-2016-10932?
CVE-2016-10932 is a man-in-the-middle vulnerability due to the lack of hostname verification.
5
Can CVE-2016-10932 be exploited remotely?
Yes, CVE-2016-10932 can be exploited remotely through interception of HTTPS traffic.