IBM Security Bulletin: Vulnerabilities in cURL component shipped with ClearCase (CVE-2014-0139)

An attacker could send a specially-crafted certificate to impersonate a server. CVE(s): CVE-2014-0139 Affected product(s) and affected version(s): The cURL component is only used in the CMI integration and in the OSLC-based...



from IBM Product Security Incident Response Team http://ibm.co/13dhazV