Heimdal Thor Agent 2.5.17x before 2.5.173 does not verify X.509 certificates from TLS servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate.
| Software | From | Fixed in |
|---|---|---|
| heimdalsecurity / thor | 2.5.170-rc | 2.5.170-rc.x |
| heimdalsecurity / thor | 2.5.171 | 2.5.171.x |
| heimdalsecurity / thor | 2.5.172 | 2.5.172.x |