Red Hat Bugzilla – Bug 845665
CVE-2012-3446 libcloud: possible SSL MITM due to invalid regexp used to validate target server hostname
Last modified: 2013-01-17 17:08:11 EST
A man-in-the-middle vulnerability was reported  in Apache Libcloud, due to an invalid regular expression used to validate the target server hostname. When establishing an SSL/TLS connection to a target server, a subset of the full target server hostname was marked as an acceptable match for the given hostname (such as a certificate specifying "aexample.com" being considered acceptable for "example.com"). Upstream version 0.11.1 includes a fix for this flaw.
Created python-libcloud tracking bugs for this issue
Affects: fedora-all [bug 845666]
Current Fedora has 0.11.4 which includes this fix.