{"id":"PYSEC-2014-93","details":"PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate.","aliases":["CVE-2013-6418","GHSA-f9q5-46qg-74x4"],"modified":"2026-06-10T17:02:31.790999873Z","published":"2014-05-05T17:06:00Z","references":[{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1039801"},{"type":"WEB","url":"http://sourceforge.net/p/pywbem/code/627/"},{"type":"ADVISORY","url":"http://secunia.com/advisories/58327"},{"type":"WEB","url":"https://www.suse.com/support/update/announcement/2014/suse-su-20140580-1.html"},{"type":"WEB","url":"http://sourceforge.net/p/pywbem/mailman/message/31757312/"},{"type":"WEB","url":"http://seclists.org/oss-sec/2013/q4/531"},{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/64544"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-f9q5-46qg-74x4"}],"affected":[{"package":{"name":"pywbem","ecosystem":"PyPI","purl":"pkg:pypi/pywbem"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.8.1"}]}],"versions":["0.7.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/pywbem/PYSEC-2014-93.yaml"}}],"schema_version":"1.7.5"}