github.com
https://github.com/hyperium/hyper/blob/master/CHANGELOG.md CVE-2016-10932
MEDIUM
HTTPS MitM vulnerability due to lack of hostname verification
Record summary
CVE-2016-10932 has a selected CVSS score of 4.8 (medium).
Description
An issue was discovered in the hyper crate before 0.9.4 for Rust on Windows. There is an HTTPS man-in-the-middle vulnerability because hostname verification was omitted.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| GitHub Advisory | Before 0.9.4 · Fixed in 0.9.4 | affected |
References
5github.com
https://github.com/hyperium/hyper/commit/01160abd92956e5f995cc45790df7a2b86c8989f github.com
https://github.com/hyperium/hyper/issues/472 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-10932 rustsec.org
https://rustsec.org/advisories/RUSTSEC-2016-0002.html