wpa_supplicant 2.0-16 does not properly check certificate subject name, which allows remote attackers to cause a man-in-the-middle attack.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1178263 | patch vdb entry exploit third party advisory issue tracking |
https://bugzilla.redhat.com/show_bug.cgi?id=1178921 | vdb entry exploit third party advisory issue tracking |