CVE-2013-1909
python-qpid: client does not validate qpid server TLS/SSL certificate
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Python client in Apache Qpid before 2.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
El cliente Python en Apache Qpid anterior a v2.2 no verifica que el nombre del servidor coincide con un nombre de dominio en el nombre común del sujeto (CN) o el campo subjectAltName del certificado X.509, permitiendo a los atacantes de hombre-en-medio (man-in-the-middle) falsificar servidores SSL mediante un certificado válido de su elección.
Updated Messaging component packages that fix one security issue and multiple bugs are now available for Red Hat Enterprise MRG 2.3 for Red Hat Enterprise Linux 6.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-02-19 CVE Reserved
- 2013-07-11 CVE Published
- 2024-09-16 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://qpid.apache.org/releases/qpid-0.22/release-notes.html | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://svn.apache.org/viewvc?view=revision&revision=1460013 | 2021-07-15 | |
https://issues.apache.org/jira/browse/QPID-4918 | 2021-07-15 |
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2013-1024.html | 2021-07-15 | |
http://secunia.com/advisories/53968 | 2021-07-15 | |
http://secunia.com/advisories/54137 | 2021-07-15 | |
https://access.redhat.com/security/cve/CVE-2013-1909 | 2013-07-11 | |
https://bugzilla.redhat.com/show_bug.cgi?id=928530 | 2013-07-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Enterprise Mrg Search vendor "Redhat" for product "Enterprise Mrg" | 2.0 Search vendor "Redhat" for product "Enterprise Mrg" and version "2.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Qpid Search vendor "Apache" for product "Qpid" | <= 0.20 Search vendor "Apache" for product "Qpid" and version " <= 0.20" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Qpid Search vendor "Apache" for product "Qpid" | 0.5 Search vendor "Apache" for product "Qpid" and version "0.5" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Qpid Search vendor "Apache" for product "Qpid" | 0.6 Search vendor "Apache" for product "Qpid" and version "0.6" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Qpid Search vendor "Apache" for product "Qpid" | 0.7 Search vendor "Apache" for product "Qpid" and version "0.7" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Qpid Search vendor "Apache" for product "Qpid" | 0.8 Search vendor "Apache" for product "Qpid" and version "0.8" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Qpid Search vendor "Apache" for product "Qpid" | 0.9 Search vendor "Apache" for product "Qpid" and version "0.9" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Qpid Search vendor "Apache" for product "Qpid" | 0.10 Search vendor "Apache" for product "Qpid" and version "0.10" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Qpid Search vendor "Apache" for product "Qpid" | 0.11 Search vendor "Apache" for product "Qpid" and version "0.11" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Qpid Search vendor "Apache" for product "Qpid" | 0.12 Search vendor "Apache" for product "Qpid" and version "0.12" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Qpid Search vendor "Apache" for product "Qpid" | 0.13 Search vendor "Apache" for product "Qpid" and version "0.13" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Qpid Search vendor "Apache" for product "Qpid" | 0.14 Search vendor "Apache" for product "Qpid" and version "0.14" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Qpid Search vendor "Apache" for product "Qpid" | 0.15 Search vendor "Apache" for product "Qpid" and version "0.15" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Qpid Search vendor "Apache" for product "Qpid" | 0.16 Search vendor "Apache" for product "Qpid" and version "0.16" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Qpid Search vendor "Apache" for product "Qpid" | 0.17 Search vendor "Apache" for product "Qpid" and version "0.17" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Qpid Search vendor "Apache" for product "Qpid" | 0.18 Search vendor "Apache" for product "Qpid" and version "0.18" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Qpid Search vendor "Apache" for product "Qpid" | 0.19 Search vendor "Apache" for product "Qpid" and version "0.19" | - |
Affected
|