{"id":"CVE-2013-1909","details":"The Python client in Apache Qpid before 2.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.","aliases":["GHSA-3g2p-7c6p-vj8c","PYSEC-2013-25"],"modified":"2024-04-29T11:26:34.852473Z","published":"2013-08-23T16:55:07Z","withdrawn":"2024-06-30T13:40:12.276837Z","references":[{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2013-1024.html"},{"type":"ADVISORY","url":"http://secunia.com/advisories/53968"},{"type":"ADVISORY","url":"http://secunia.com/advisories/54137"},{"type":"FIX","url":"http://svn.apache.org/viewvc?view=revision&revision=1460013"},{"type":"FIX","url":"https://issues.apache.org/jira/browse/QPID-4918"},{"type":"WEB","url":"http://qpid.apache.org/releases/qpid-0.22/release-notes.html"}],"affected":[{"package":{"name":"qpid-python","ecosystem":"Debian:10","purl":"pkg:deb/debian/qpid-python?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.22-1"}]}],"ecosystem_specific":{"urgency":"low"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2013-1909.json"}}],"schema_version":"1.7.3"}