MEDIUM · 5.8

CVE-2011-4092

obby (aka libobby) does not verify SSL server certificates, which allows remote attackers to spoof servers via an arbitrary certificate.

Vulnerability Description

obby (aka libobby) does not verify SSL server certificates, which allows remote attackers to spoof servers via an arbitrary certificate.

CVSS Score

5.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
Ubuntu DevelopersObby-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-4092?

CVE-2011-4092 is a vulnerability with a CVSS score of 5.8 (MEDIUM). obby (aka libobby) does not verify SSL server certificates, which allows remote attackers to spoof servers via an arbitrary certificate.

How severe is CVE-2011-4092?

CVE-2011-4092 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-4092?

Check the references section above for vendor advisories and patch information. Affected products include: Ubuntu Developers Obby.