CVE-2013-0243: Input Validation
Published Dec 5, 2019
·Updated
haskell-tls-extra before 0.6.1 has Basic Constraints attribute vulnerability may lead to Man in the Middle attacks on TLS connections
Affected Software
2 affected components
debian/haskell-tls-extra
haskell Hs-tls<0.6.1
Event History
Dec 5, 2019
CVE Published
via MITRE·03:16 PM
Data Sourced
via MITRE·03:16 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2013-0243?
CVE-2013-0243 has a high severity rating due to its potential to allow Man in the Middle attacks on TLS connections.
2
How do I fix CVE-2013-0243?
To fix CVE-2013-0243, update the affected haskell-tls-extra package to version 0.6.1 or later.
3
What systems are affected by CVE-2013-0243?
CVE-2013-0243 affects versions of haskell-tls-extra before 0.6.1 and the hs-tls package prior to the same version.
4
What types of attacks can CVE-2013-0243 enable?
CVE-2013-0243 can enable Man in the Middle attacks, compromising the security of TLS connections.
5
Is CVE-2013-0243 relevant to my software?
If you are using haskell-tls-extra or hs-tls versions prior to 0.6.1, CVE-2013-0243 is highly relevant to your software.