Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sun, 4 May 2014 08:26:25 +0200
From: Salvatore Bonaccorso <>
Cc: Assign a CVE Identifier <>,
	Steffen Ullrich <>
Subject: Re: Debian Bug#746579: libwww-perl: HTTPS_CA_DIR or
 HTTPS_CA_FILE disables peer certificate verification for IO::Socket::SSL


On Fri, May 02, 2014 at 02:54:33PM -0600, Kurt Seifried wrote:
> Hash: SHA1
> Package: libwww-perl
> Version: 6.06-1
> Tags: security
> Usertags: serious
> If LWP uses IO::Socket::SSL as SSL socket class (this is the default),
> setting HTTPS_CA_DIR or HTTPS_CA_FILE environment variable disables(!)
> server cerificate verification:

An update on this issue for the affected versions:

Steffen Ullrich proposed a fix for this in [1]. The issue seem to be
introduced in LWP::Protocol::https in commit[2], which is version



Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.