CVE-2009-3024

Source
https://cve.org/CVERecord?id=CVE-2009-3024
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2009-3024.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2009-3024
Downstream
Published
2009-08-31T20:30:01Z
Modified
2026-04-10T03:40:52.983810Z
Summary
[none]
Details

The verifyhostnameof_cert function in the certificate checking feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through 1.25 only matches the prefix of a hostname when no wildcard is used, which allows remote attackers to bypass the hostname check for a certificate.

References

Affected packages