CVE-2003-0370
published 2003-06-16CVE-2003-0370: Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof…
PriorityP423high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.06%
79.2th percentile
Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | — | — |
| kde | kde | <= 2.2.2 | — |
| kde | konqueror_embedded | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| turbolinux | turbolinux_server | — | — |
| turbolinux | turbolinux_server | — | — |
| turbolinux | turbolinux_workstation | — | — |
| turbolinux | turbolinux_workstation | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9cxf-vv6j-h6r9: Konqueror Embedded and KDE 2
ghsa_unreviewed·2022-04-29
CVE-2003-0370 [HIGH] GHSA-9cxf-vv6j-h6r9: Konqueror Embedded and KDE 2
Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.
Red Hat
security flaw
vendor_redhat·2003-06-02·CVSS 7.5
CVE-2003-0370 [HIGH] security flaw
security flaw
Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2003-0370 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2003-0370 [HIGH] CVE-2003-0370 security flaw
CVE-2003-0370 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.
Bugzilla
CAN-2003-0370 KDE SSL CA checking implementation vulnerability
bugzilla·2003-06-03
[MEDIUM] CAN-2003-0370 KDE SSL CA checking implementation vulnerability
CAN-2003-0370 KDE SSL CA checking implementation vulnerability
Versions of KDE 2.2.2 and earlier have a vulnerability in their SSL
implementation that makes it possible for users of Konqueror and other SSL
enabled KDE software to fall victim to a man-in-the-middle attack.
Users of KDE should upgrade to the erratum packages currently in progress which
will contain KDE 2.2.2 with a backported patch to correct this vulnerability.
RHSA-2003:193
CVE applied for
Discussion:
An errata has been issued which should help the problem described in this bug report.
This report is therefore being closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files, please follow the link below. You may reopen
this bug report if the solution does not work f
http://lists.grok.org.uk/pipermail/full-disclosure/2003-May/004983.htmlhttp://www.debian.org/security/2003/dsa-361http://www.kde.org/info/security/advisory-20030602-1.txthttp://www.redhat.com/support/errata/RHSA-2003-192.htmlhttp://www.redhat.com/support/errata/RHSA-2003-193.htmlhttp://www.securityfocus.com/archive/1/320707http://www.securityfocus.com/bid/7520http://www.turbolinux.com/security/TLSA-2003-36.txthttp://lists.grok.org.uk/pipermail/full-disclosure/2003-May/004983.htmlhttp://www.debian.org/security/2003/dsa-361http://www.kde.org/info/security/advisory-20030602-1.txthttp://www.redhat.com/support/errata/RHSA-2003-192.htmlhttp://www.redhat.com/support/errata/RHSA-2003-193.htmlhttp://www.securityfocus.com/archive/1/320707http://www.securityfocus.com/bid/7520http://www.turbolinux.com/security/TLSA-2003-36.txt
2003-06-16
Published