USN-8907-1: libgit2 vulnerability
Ubuntu warns libgit2 TLS IP certificate checks can enable a machine-in-the-middle attack.
Ubuntu Security Notice USN-8907-1 says libgit2 incorrectly verified IP address SubjectAltName entries during TLS certificate validation. A remote attacker with a CA-trusted certificate could use the flaw for a machine-in-the-middle attack and expose sensitive information. The notice does not name a CVE or report observed exploitation.
- libgit2 mishandled IP address SubjectAltName checks in TLS validation.
- A remote attacker with a CA-trusted certificate could intercept traffic.
- The impact is possible exposure of sensitive information.
- Ubuntu issued the warning as USN-8907-1; no CVE is named.
It was discovered that libgit2 incorrectly handled IP address SubjectAltName verification in TLS certificate validation. A remote attacker with a CA-trusted certificate could possibly use this issue to perform a machine-in-the-middle attack, leading to the exposure of sensitive information.
This source does not provide full text. Read it at ubuntu.com.