Medium severity5.9NVD Advisory· Published Jan 28, 2020· Updated Jun 17, 2026
CVE-2014-3230
CVE-2014-3230
Description
The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl, when using IO::Socket::SSL as the SSL socket class, allows attackers to disable server certificate validation via the (1) HTTPS_CA_DIR or (2) HTTPS_CA_FILE environment variable.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Range: 6.04 - 6.06
- Range: 6.04 - 6.06
- libwww-perl/LWP::Protocol::httpsv5Range: 6.04 through 6.06
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2014/05/04/1nvdMailing ListPatchThird Party Advisory
- bugs.debian.org/cgi-bin/bugreport.cginvdExploitMailing ListPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2014/05/02/8nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2014/05/06/8nvdMailing ListThird Party Advisory
- github.com/libwww-perl/lwp-protocol-https/pull/14nvdBroken Link
News mentions
0No linked articles in our index yet.