CVE-2014-0350
published 2014-04-26CVE-2014-0350: The Poco::Net::X509Certificate::verify method in the NetSSL library in POCO C++ Libraries before 1.4.6p4 allows man-in-the-middle attackers to spoof SSL…
PriorityP426medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
1.22%
65.6th percentile
The Poco::Net::X509Certificate::verify method in the NetSSL library in POCO C++ Libraries before 1.4.6p4 allows man-in-the-middle attackers to spoof SSL servers via crafted DNS PTR records that are requested during comparison of a server name to a wildcard domain name in an X.509 certificate.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | poco | < poco 1.3.6p1-5 (bookworm) | poco 1.3.6p1-5 (bookworm) |
| pocoproject | poco | >= 0 < 1.3.6p1-5 | 1.3.6p1-5 |
| pocoproject | poco | >= 0 < 1.3.6p1-5 | 1.3.6p1-5 |
| pocoproject | poco | >= 0 < 1.3.6p1-5 | 1.3.6p1-5 |
| pocoproject | poco | >= 0 < 1.3.6p1-5 | 1.3.6p1-5 |
| pocoproject | poco_c_+_+_libraries | <= 1.4.6 | — |
| pocoproject | poco_c_+_+_libraries | — | — |
| pocoproject | poco_c_+_+_libraries | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.4MEDIUM
vendor_debian6.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
POCO C++ Libraries up to 1.4.5 verify cryptographic issue (FEDORA-2016-0b3a611401 / VU#118748)
vuldb·2026-05-12·CVSS 6.4
CVE-2014-0350 [MEDIUM] POCO C++ Libraries up to 1.4.5 verify cryptographic issue (FEDORA-2016-0b3a611401 / VU#118748)
A vulnerability categorized as critical has been discovered in POCO C++ Libraries up to 1.4.5. This vulnerability affects the function Poco::Net::X509Certificate::verify of the component Libraries. Executing a manipulation can lead to cryptographic issues.
This vulnerability is registered as CVE-2014-0350. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
GHSA
GHSA-whgv-p774-rw69: The Poco::Net::X509Certificate::verify method in the NetSSL library in POCO C++ Libraries before 1
ghsa_unreviewed·2022-05-17
CVE-2014-0350 [MEDIUM] GHSA-whgv-p774-rw69: The Poco::Net::X509Certificate::verify method in the NetSSL library in POCO C++ Libraries before 1
The Poco::Net::X509Certificate::verify method in the NetSSL library in POCO C++ Libraries before 1.4.6p4 allows man-in-the-middle attackers to spoof SSL servers via crafted DNS PTR records that are requested during comparison of a server name to a wildcard domain name in an X.509 certificate.
OSV
CVE-2014-0350: The Poco::Net::X509Certificate::verify method in the NetSSL library in POCO C++ Libraries before 1
osv·2014-04-26·CVSS 6.4
CVE-2014-0350 [MEDIUM] CVE-2014-0350: The Poco::Net::X509Certificate::verify method in the NetSSL library in POCO C++ Libraries before 1
The Poco::Net::X509Certificate::verify method in the NetSSL library in POCO C++ Libraries before 1.4.6p4 allows man-in-the-middle attackers to spoof SSL servers via crafted DNS PTR records that are requested during comparison of a server name to a wildcard domain name in an X.509 certificate.
Debian
CVE-2014-0350: poco - The Poco::Net::X509Certificate::verify method in the NetSSL library in POCO C++ ...
vendor_debian·2014·CVSS 6.4
CVE-2014-0350 [MEDIUM] CVE-2014-0350: poco - The Poco::Net::X509Certificate::verify method in the NetSSL library in POCO C++ ...
The Poco::Net::X509Certificate::verify method in the NetSSL library in POCO C++ Libraries before 1.4.6p4 allows man-in-the-middle attackers to spoof SSL servers via crafted DNS PTR records that are requested during comparison of a server name to a wildcard domain name in an X.509 certificate.
Scope: local
bookworm: resolved (fixed in 1.3.6p1-5)
bullseye: resolved (fixed in 1.3.6p1-5)
forky: resolved (fixed in 1.3.6p1-5)
sid: resolved (fixed in 1.3.6p1-5)
trixie: resolved (fixed in 1.3.6p1-5)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0350 poco: certificate validation issue [epel-all]
bugzilla·2014-04-28·CVSS 6.4
CVE-2014-0350 [MEDIUM] CVE-2014-0350 poco: certificate validation issue [epel-all]
CVE-2014-0350 poco: certificate validation issue [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple supported ver
Bugzilla
CVE-2014-0350 poco: certificate validation issue [fedora-all]
bugzilla·2014-04-28·CVSS 6.4
CVE-2014-0350 [MEDIUM] CVE-2014-0350 poco: certificate validation issue [fedora-all]
CVE-2014-0350 poco: certificate validation issue [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple supported versio
Bugzilla
CVE-2014-0350 poco: certificate validation issue
bugzilla·2014-04-28·CVSS 6.4
CVE-2014-0350 [MEDIUM] CVE-2014-0350 poco: certificate validation issue
CVE-2014-0350 poco: certificate validation issue
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-0350 to
the following vulnerability:
Name: CVE-2014-0350
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0350
Assigned: 20131205
Reference: https://raw.githubusercontent.com/pocoproject/poco/poco-1.4.6p4-release/CHANGELOG
Reference: CERT-VN:VU#118748
Reference: http://www.kb.cert.org/vuls/id/118748
The Poco::Net::X509Certificate::verify method in the NetSSL library in
POCO C++ Libraries before 1.4.6p4 allows man-in-the-middle attackers
to spoof SSL servers via crafted DNS PTR records that are requested
during comparison of a server name to a wildcard domain name in an
X.509 certificate.
This issue has been fixed in version 1.4.6p4 and later.
Discussion:
Cr
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177471.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/177573.htmlhttp://www.kb.cert.org/vuls/id/118748https://raw.githubusercontent.com/pocoproject/poco/poco-1.4.6p4-release/CHANGELOGhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/177471.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/177573.htmlhttp://www.kb.cert.org/vuls/id/118748https://raw.githubusercontent.com/pocoproject/poco/poco-1.4.6p4-release/CHANGELOG
2014-04-26
Published