CVE-2003-0370

6 documents5 sources
Severity
7.5HIGH
EPSS
0.9%
top 23.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 16
Latest updateApr 29

Description

Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages6 packages

NVDkde/kde2.2.2
NVDapple/safari1.0
NVDredhat/linux7.1, 7.2+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9cxf-vv6j-h6r9: Konqueror Embedded and KDE 22022-04-29
CVEList
CVE-2003-0370: Konqueror Embedded and KDE 22003-06-05

📋Vendor Advisories

1
Red Hat
security flaw2003-06-02

💬Community

2
Bugzilla
CVE-2003-0370 security flaw2018-08-16
Bugzilla
CAN-2003-0370 KDE SSL CA checking implementation vulnerability2003-06-03