CVE-2011-0633 - CVE House
Back to Database
Status published Medium CVE-2011-0633

The Net::HTTPS module in libwww-perl (LWP) before 6.00, as used...

Vulnerability Description

The Net::HTTPS module in libwww-perl (LWP) before 6.00, as used in WWW::Mechanize, LWP::UserAgent, and other products, when running in environments that do not set the If-SSL-Cert-Subject header, does not enable full validation of SSL certificates by default, which allows remote attackers to spoof servers via man-in-the-middle (MITM) attacks involving hostnames that are not properly validated. NOTE: it could be argued that this is a design limitation of the Net::HTTPS API, and separate implementations should be independently assigned CVE identifiers for not working around this limitation. However, because this API was modified within LWP, a single CVE identifier has been assigned.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-0633

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

libwww-perl
Vulnerable Versions:
0.01, 0.02, 0.03, 0.04, 5.00, 5.01, 5.02, 5.03, 5.04, 5.05, 5.06, 5.07, 5.08, 5.09, 5.10, 5.11, 5.12, 5.13, 5.14, 5.15, 5.16, 5.17, 5.18, 5.18_03, 5.18_04, 5.18_05, 5.19, 5.20, 5.21, 5.22, 5.30, 5.31, 5.32, 5.33, 5.34, 5.35, 5.36, 5.41, 5.42, 5.43, 5.44, 5.45, 5.46, 5.47, 5.48, 5.49, 5.50, 5.51, 5.52, 5.53, 5.53_90, 5.53_91, 5.53_92, 5.53_93, 5.53_94, 5.53_95, 5.53_96, 5.53_97, 5.60, 5.61, 5.62, 5.63, 5.64, 5.65, 5.66, 5.67, 5.68, 5.69, 5.70, 5.71, 5.72, 5.73, 5.74, 5.75, 5.76, 5.77, 5.78, 5.79, 5.800, 5.801, 5.802, 5.803, 5.804, 5.805, 5.806, 5.807, 5.808, 5.810, 5.811, 5.812, 5.813, 5.814, 5.815, 5.816, 5.817, 5.818, 5.819, 5.820, 5.821, 5.822, 5.823, 5.824, 5.825, 5.826, 5.827, 5.828, 5.829, 5.830, 5.831, 5.832, 5.833, 5.834, 5.836, 5b5, 5b6, 5b7, 5b8, 5b9, 5b10, 5b11, 5b12, 5b13, 0, 5.40_01

Timeline

Official Publish: May 13th, 2011
Last Modified: September 16th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.