CVE-2009-2408
published 2009-07-30CVE-2009-2408: Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a…
PriorityP430medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
5.74%
92.2th percentile
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. NOTE: this was originally reported for Firefox before 3.5.
Affected
921 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.6.5 | 10.6.5 |
| apple | mac_os_x | < 10.6.2 | 10.6.2 |
| apple | mac_os_x | <= 10.6.1 | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv5.9MEDIUM
vendor_ubuntu9.3CRITICAL
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hhfm-3287-cc2v: The openssl_x509_parse function in openssl
ghsa_unreviewed·2022-05-17·CVSS 5.9
CVE-2013-4248 [MEDIUM] CWE-20 GHSA-hhfm-3287-cc2v: The openssl_x509_parse function in openssl
The openssl_x509_parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-xwjm-4v2q-p47f: istream
ghsa_unreviewed·2022-05-17·CVSS 5.9
CVE-2010-2074 [MEDIUM] CWE-20 GHSA-xwjm-4v2q-p47f: istream
istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is enabled, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-3gpq-xx45-4rr9: The OpenSSL::SSL
ghsa_unreviewed·2022-05-14·CVSS 5.9
CVE-2013-4073 [MEDIUM] GHSA-3gpq-xx45-4rr9: The OpenSSL::SSL
The OpenSSL::SSL.verify_certificate_identity function in lib/openssl/ssl.rb in Ruby 1.8 before 1.8.7-p374, 1.9 before 1.9.3-p448, and 2.0 before 2.0.0-p247 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-vp8q-678w-8xq9: The ssl
ghsa_unreviewed·2022-05-13·CVSS 5.9
CVE-2013-4238 [MEDIUM] CWE-20 GHSA-vp8q-678w-8xq9: The ssl
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-c74q-xg62-9cwm: lib/ssluse
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2009-2417 [MEDIUM] GHSA-c74q-xg62-9cwm: lib/ssluse
lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-r4xr-x22c-68gg: Google Chrome, possibly 3
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2009-3456 [MEDIUM] GHSA-r4xr-x22c-68gg: Google Chrome, possibly 3
Google Chrome, possibly 3.0.195.21 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
GHSA
GHSA-hc4m-gmh3-4vxp: libraries/libldap/tls_o
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2009-3767 [MEDIUM] CWE-295 GHSA-hc4m-gmh3-4vxp: libraries/libldap/tls_o
libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-x9rv-vww8-vmj9: neon before 0
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2009-2474 [MEDIUM] CWE-326 GHSA-x9rv-vww8-vmj9: neon before 0
neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-6p5c-44cm-r9m8: GNU Wget before 1
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2009-3490 [MEDIUM] GHSA-6p5c-44cm-r9m8: GNU Wget before 1
GNU Wget before 1.12 does not properly handle a '\0' character in a domain name in the Common Name field of an X.509 certificate, which allows man-in-the-middle remote attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-g4p5-56vp-vcg5: sendmail before 8
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2009-4565 [MEDIUM] GHSA-g4p5-56vp-vcg5: sendmail before 8
sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-fp73-6h6h-9v4h: mutt_ssl
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2009-3765 [MEDIUM] GHSA-fp73-6h6h-9v4h: mutt_ssl
mutt_ssl.c in mutt 1.5.19 and 1.5.20, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-4vq9-9g4j-pgg4: The mod_tls module in ProFTPD before 1
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2009-3639 [MEDIUM] GHSA-4vq9-9g4j-pgg4: The mod_tls module in ProFTPD before 1
The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, which allows remote attackers to bypass intended client-hostname restrictions via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-65q5-4r9q-gp26: KDE KSSL in kdelibs 3
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2009-2702 [MEDIUM] GHSA-65q5-4r9q-gp26: KDE KSSL in kdelibs 3
KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-fq9p-mw8p-ccwj: Martin Lambers msmtp before 1
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2009-3942 [MEDIUM] GHSA-fq9p-mw8p-ccwj: Martin Lambers msmtp before 1
Martin Lambers msmtp before 1.4.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-xcxh-pxhq-2wrw: src/network/ssl/qsslcertificate
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2009-2700 [MEDIUM] CWE-20 GHSA-xcxh-pxhq-2wrw: src/network/ssl/qsslcertificate
src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-6g82-jmg8-h26c: The Blackberry Browser in RIM BlackBerry Device Software 4
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2009-3477 [MEDIUM] GHSA-6g82-jmg8-h26c: The Blackberry Browser in RIM BlackBerry Device Software 4
The Blackberry Browser in RIM BlackBerry Device Software 4.5.0 before 4.5.0.173, 4.6.0 before 4.6.0.303, 4.6.1 before 4.6.1.309, 4.7.0 before 4.7.0.179, and 4.7.1 before 4.7.1.57 does not properly handle "hidden" characters including a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows remote man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-2hgw-48gj-v3wx: Apple Safari, possibly before 4
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2009-3455 [MEDIUM] GHSA-2hgw-48gj-v3wx: Apple Safari, possibly before 4
Apple Safari, possibly before 4.0.3, on Mac OS X does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-g2h9-5v79-gp76: libESMTP, probably 1
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2010-1192 [MEDIUM] GHSA-g2h9-5v79-gp76: libESMTP, probably 1
libESMTP, probably 1.0.4 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-vh9w-973v-hmhv: Certificate Assistant in Apple Mac OS X before 10
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2009-2825 [MEDIUM] GHSA-vh9w-973v-hmhv: Certificate Assistant in Apple Mac OS X before 10
Certificate Assistant in Apple Mac OS X before 10.6.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-6wgc-gv8j-fmpq: PostgreSQL 7
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2009-4034 [MEDIUM] GHSA-6wgc-gv8j-fmpq: PostgreSQL 7
PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based PostgreSQL servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended client-hostname restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-g23p-47j7-w4hw: Internet2 Shibboleth Service Provider software 1
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2009-3475 [MEDIUM] GHSA-g23p-47j7-w4hw: Internet2 Shibboleth Service Provider software 1
Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before 2.2.1, when using PKIX trust validation, does not properly handle a '\0' character in the subject or subjectAltName fields of a certificate, which allows remote man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-37wj-ffhc-82xv: Martin Lambers mpop before 1
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2009-3941 [MEDIUM] GHSA-37wj-ffhc-82xv: Martin Lambers mpop before 1
Martin Lambers mpop before 1.0.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
GHSA
GHSA-3jw8-9rgf-396w: The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Serv
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2009-2510 [MEDIUM] GHSA-3jw8-9rgf-396w: The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Serv
The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, as used by Internet Explorer and other applications, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, aka "Null Truncation in X.509 Common Name Vulnerability," a related issue to CVE-2009-2408.
GHSA
GHSA-pm7c-vg9h-jxxc: Mozilla Network Security Services (NSS) before 3
ghsa_unreviewed·2022-05-02
CVE-2009-2408 [MEDIUM] CWE-20 GHSA-pm7c-vg9h-jxxc: Mozilla Network Security Services (NSS) before 3
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. NOTE: this was originally reported for Firefox before 3.5.
GHSA
GHSA-f5g6-55mc-jx72: socket
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2009-2666 [MEDIUM] GHSA-f5g6-55mc-jx72: socket
socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
OSV
CVE-2013-4238: The ssl
osv·2013-08-18·CVSS 5.9
CVE-2013-4238 [MEDIUM] CVE-2013-4238: The ssl
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
OSV
CVE-2010-2074: istream
osv·2010-06-16·CVSS 5.9
CVE-2010-2074 [MEDIUM] CVE-2010-2074: istream
istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is enabled, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
OSV
CVE-2010-1192: libESMTP, probably 1
osv·2010-03-31·CVSS 5.9
CVE-2010-1192 [MEDIUM] CVE-2010-1192: libESMTP, probably 1
libESMTP, probably 1.0.4 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
OSV
CVE-2009-4565: sendmail before 8
osv·2010-01-04·CVSS 5.9
CVE-2009-4565 [MEDIUM] CVE-2009-4565: sendmail before 8
sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
OSV
CVE-2009-3941: Martin Lambers mpop before 1
osv·2009-11-16·CVSS 5.9
CVE-2009-3941 [MEDIUM] CVE-2009-3941: Martin Lambers mpop before 1
Martin Lambers mpop before 1.0.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
OSV
CVE-2009-3639: The mod_tls module in ProFTPD before 1
osv·2009-10-28·CVSS 5.9
CVE-2009-3639 [MEDIUM] CVE-2009-3639: The mod_tls module in ProFTPD before 1
The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, which allows remote attackers to bypass intended client-hostname restrictions via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
OSV
CVE-2009-3767: libraries/libldap/tls_o
osv·2009-10-23·CVSS 5.9
CVE-2009-3767 [MEDIUM] CVE-2009-3767: libraries/libldap/tls_o
libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
OSV
CVE-2009-3490: GNU Wget before 1
osv·2009-09-30·CVSS 5.9
CVE-2009-3490 [MEDIUM] CVE-2009-3490: GNU Wget before 1
GNU Wget before 1.12 does not properly handle a '\0' character in a domain name in the Common Name field of an X.509 certificate, which allows man-in-the-middle remote attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
OSV
CVE-2009-3475: Internet2 Shibboleth Service Provider software 1
osv·2009-09-29·CVSS 5.9
CVE-2009-3475 [MEDIUM] CVE-2009-3475: Internet2 Shibboleth Service Provider software 1
Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before 2.2.1, when using PKIX trust validation, does not properly handle a '\0' character in the subject or subjectAltName fields of a certificate, which allows remote man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
OSV
CVE-2009-2702: KDE KSSL in kdelibs 3
osv·2009-09-08·CVSS 5.9
CVE-2009-2702 [MEDIUM] CVE-2009-2702: KDE KSSL in kdelibs 3
KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
OSV
CVE-2009-2700: src/network/ssl/qsslcertificate
osv·2009-09-02·CVSS 5.9
CVE-2009-2700 [MEDIUM] CVE-2009-2700: src/network/ssl/qsslcertificate
src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
OSV
CVE-2009-2474: neon before 0
osv·2009-08-21·CVSS 5.9
CVE-2009-2474 [MEDIUM] CVE-2009-2474: neon before 0
neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
OSV
CVE-2009-2417: lib/ssluse
osv·2009-08-14·CVSS 5.9
CVE-2009-2417 [MEDIUM] CVE-2009-2417: lib/ssluse
lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
OSV
CVE-2009-2666: socket
osv·2009-08-07·CVSS 5.9
CVE-2009-2666 [MEDIUM] CVE-2009-2666: socket
socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
OSV
CVE-2009-2408: Mozilla Network Security Services (NSS) before 3
osv·2009-07-30·CVSS 5.9
CVE-2009-2408 [MEDIUM] CVE-2009-2408: Mozilla Network Security Services (NSS) before 3
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. NOTE: this was originally reported for Firefox before 3.5.
Red Hat
php: hostname check bypassing vulnerability in SSL client
vendor_redhat·2013-08-13·CVSS 5.9
CVE-2013-4248 [MEDIUM] php: hostname check bypassing vulnerability in SSL client
php: hostname check bypassing vulnerability in SSL client
The openssl_x509_parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Statement: This issue does not affect the version of php as shipped with Red Hat Enterprise Linux 5 or the version of php54 as shipped with Red Hat Software Collections 1.
Package: php (Red Hat Enterprise Linux 5) - Not affected
Package: php (Red Hat Enterprise Linux 7) - Not affected
Package: php54-php (Red Hat Software C
Red Hat
python: hostname check bypassing vulnerability in SSL module
vendor_redhat·2013-08-12·CVSS 5.9
CVE-2013-4238 [MEDIUM] python: hostname check bypassing vulnerability in SSL module
python: hostname check bypassing vulnerability in SSL module
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Statement: This issue does not affect the version of python as shipped with Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this issue as having moderate security impact, a future update may address this flaw.
Package: python (Red Hat Enterprise Linux 5) - Not affected
Package: python (Red Hat Enterprise Linux 7) - Not affected
P
Red Hat
ruby: hostname check bypassing vulnerability in SSL client
vendor_redhat·2013-06-27·CVSS 5.9
CVE-2013-4073 [MEDIUM] ruby: hostname check bypassing vulnerability in SSL client
ruby: hostname check bypassing vulnerability in SSL client
The OpenSSL::SSL.verify_certificate_identity function in lib/openssl/ssl.rb in Ruby 1.8 before 1.8.7-p374, 1.9 before 1.9.3-p448, and 2.0 before 2.0.0-p247 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Package: ruby (Red Hat Enterprise Linux 7) - Not affected
Package: jruby (Red Hat JBoss SOA Platform 4) - Will not fix
Package: jruby (Red Hat JBoss SOA Platform 5) - Will not fix
Package: ruby193-ruby (Red Hat Software Collections) - Affected
Package: ruby193-ruby (Red Hat Su
Debian
CVE-2013-4238: python2.7 - The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does...
vendor_debian·2013·CVSS 5.9
CVE-2013-4238 [MEDIUM] CVE-2013-4238: python2.7 - The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does...
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Scope: local
bullseye: resolved (fixed in 2.7.5-8)
Debian
CVE-2013-4073: puppet - The OpenSSL::SSL.verify_certificate_identity function in lib/openssl/ssl.rb in R...
vendor_debian·2013·CVSS 5.9
CVE-2013-4073 [MEDIUM] CVE-2013-4073: puppet - The OpenSSL::SSL.verify_certificate_identity function in lib/openssl/ssl.rb in R...
The OpenSSL::SSL.verify_certificate_identity function in lib/openssl/ssl.rb in Ruby 1.8 before 1.8.7-p374, 1.9 before 1.9.3-p448, and 2.0 before 2.0.0-p247 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Scope: local
bullseye: resolved
Red Hat
w3m: doesn't handle NULL in Common Name properly
vendor_redhat·2010-06-14·CVSS 5.9
CVE-2010-2074 [MEDIUM] w3m: doesn't handle NULL in Common Name properly
w3m: doesn't handle NULL in Common Name properly
istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is enabled, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Package: w3m (Red Hat Enterprise Linux 6) - Not affected
Red Hat
libESMTP: Multiple certificate validation flaws
vendor_redhat·2010-03-03·CVSS 5.9
CVE-2010-1192 [MEDIUM] libESMTP: Multiple certificate validation flaws
libESMTP: Multiple certificate validation flaws
libESMTP, probably 1.0.4 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Package: libesmtp (Red Hat Enterprise Linux 6) - Affected
Debian
CVE-2010-2074: w3m - istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is en...
vendor_debian·2010·CVSS 5.9
CVE-2010-2074 [MEDIUM] CVE-2010-2074: w3m - istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is en...
istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is enabled, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Scope: local
bookworm: resolved (fixed in 0.5.2-5)
bullseye: resolved (fixed in 0.5.2-5)
forky: resolved (fixed in 0.5.2-5)
sid: resolved (fixed in 0.5.2-5)
trixie: resolved (fixed in 0.5.2-5)
Debian
CVE-2010-1192: libesmtp - libESMTP, probably 1.0.4 and earlier, does not properly handle a '\0' character ...
vendor_debian·2010·CVSS 5.9
CVE-2010-1192 [MEDIUM] CVE-2010-1192: libesmtp - libESMTP, probably 1.0.4 and earlier, does not properly handle a '\0' character ...
libESMTP, probably 1.0.4 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Scope: local
bookworm: resolved (fixed in 1.0.4-5)
bullseye: resolved (fixed in 1.0.4-5)
forky: resolved (fixed in 1.0.4-5)
sid: resolved (fixed in 1.0.4-5)
trixie: resolved (fixed in 1.0.4-5)
Red Hat
sendmail: incorrect verification of SSL certificate with NUL in name
vendor_redhat·2009-12-30·CVSS 5.9
CVE-2009-4565 [MEDIUM] sendmail: incorrect verification of SSL certificate with NUL in name
sendmail: incorrect verification of SSL certificate with NUL in name
sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Red Hat
postgresql: incorrect verification of SSL certificates with NUL in name
vendor_redhat·2009-12-09·CVSS 5.9
CVE-2009-4034 [MEDIUM] postgresql: incorrect verification of SSL certificates with NUL in name
postgresql: incorrect verification of SSL certificates with NUL in name
PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based PostgreSQL servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended client-hostname restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Statement: This issue is only security-relevant in PostgreSQL versions 8.4 and later as previou
Red Hat
mpop NULL character certificate flaw
vendor_redhat·2009-10-24·CVSS 5.9
CVE-2009-3941 [MEDIUM] mpop NULL character certificate flaw
mpop NULL character certificate flaw
Martin Lambers mpop before 1.0.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Red Hat
msmtp SSL NULL prefix flaw
vendor_redhat·2009-10-24·CVSS 5.9
CVE-2009-3942 [MEDIUM] msmtp SSL NULL prefix flaw
msmtp SSL NULL prefix flaw
Martin Lambers msmtp before 1.4.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Ubuntu
NSS regression
vendor_ubuntu·2009-09-02·CVSS 9.3
[CRITICAL] NSS regression
Title: NSS regression
Summary: NSS regression
USN-810-1 fixed vulnerabilities in NSS. Jozsef Kadlecsik noticed that
the new libraries on amd64 did not correctly set stack memory flags,
and caused applications using NSS (e.g. Firefox) to have an executable
stack. This reduced the effectiveness of some defensive security
protections. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Moxie Marlinspike discovered that NSS did not properly handle regular
expressions in certificate names. A remote attacker could create a
specially crafted certificate to cause a denial of service (via application
crash) or execute arbitrary code as the user invoking the program.
(CVE-2009-2404)
Moxie Marlinspike and Dan Kaminsky independently discovered that NSS d
Red Hat
kdelibs: kssl incorrect verification of SSL certificate with NUL in subjectAltName
vendor_redhat·2009-09-01·CVSS 5.9
CVE-2009-2702 [MEDIUM] CWE-626 kdelibs: kssl incorrect verification of SSL certificate with NUL in subjectAltName
kdelibs: kssl incorrect verification of SSL certificate with NUL in subjectAltName
KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Statement: This issue did not affect kdelibs packages as shipped in Red Hat Enterprise Linux 3 and 4.
The Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw in Red Hat Enterprise Linux 5.
Package: kdelibs (Red Hat Enterprise Linux 5) - Will not fix
Red Hat
Qt: QSslCertificate incorrect verification of SSL certificate with NUL in subjectAltName
vendor_redhat·2009-08-28·CVSS 5.9
CVE-2009-2700 [MEDIUM] Qt: QSslCertificate incorrect verification of SSL certificate with NUL in subjectAltName
Qt: QSslCertificate incorrect verification of SSL certificate with NUL in subjectAltName
src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Statement: Not vulnerable. This issue did not affect the versions of qt and qt4 as shipped with Red Hat Enterprise Linux 3, 4, or 5. Affected code was introduced upstream in version 4.3.
Red Hat
neon: Improper verification of x509v3 certificate with NULL (zero) byte in certain fields
vendor_redhat·2009-08-18·CVSS 5.9
CVE-2009-2474 [MEDIUM] neon: Improper verification of x509v3 certificate with NULL (zero) byte in certain fields
neon: Improper verification of x509v3 certificate with NULL (zero) byte in certain fields
neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Red Hat
curl: incorrect verification of SSL certificate with NUL in name
vendor_redhat·2009-08-12·CVSS 5.9
CVE-2009-2417 [MEDIUM] curl: incorrect verification of SSL certificate with NUL in name
curl: incorrect verification of SSL certificate with NUL in name
lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Red Hat
wget: incorrect verification of SSL certificate with NUL in name
vendor_redhat·2009-08-12·CVSS 5.9
CVE-2009-3490 [MEDIUM] wget: incorrect verification of SSL certificate with NUL in name
wget: incorrect verification of SSL certificate with NUL in name
GNU Wget before 1.12 does not properly handle a '\0' character in a domain name in the Common Name field of an X.509 certificate, which allows man-in-the-middle remote attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Red Hat
mutt: Doesn't properly handle NULL character in subject Common Name
vendor_redhat·2009-08-11·CVSS 5.9
CVE-2009-3765 [MEDIUM] mutt: Doesn't properly handle NULL character in subject Common Name
mutt: Doesn't properly handle NULL character in subject Common Name
mutt_ssl.c in mutt 1.5.19 and 1.5.20, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Statement: Not vulnerable. This issue did not affect the versions of mutt as shipped with Red Hat Enterprise Linux 3, 4, or 5.
Red Hat
OpenLDAP: Doesn't properly handle NULL character in subject Common Name
vendor_redhat·2009-08-10·CVSS 5.9
CVE-2009-3767 [MEDIUM] OpenLDAP: Doesn't properly handle NULL character in subject Common Name
OpenLDAP: Doesn't properly handle NULL character in subject Common Name
libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Statement: This issue was addressed in the openldap packages as shipped with Red Hat Enterprise Linux 5 and 4 via: https://rhn.redhat.com/errata/RHSA-2010-0198.html and https://rhn.redhat.com/errata/RHSA-2010-0543.html respectively.
The Red Hat Security Response Team has rated this issue as having moderate security imp
Red Hat
ProFTPD: Doesn't properly handle NULL character in subjectAltName
vendor_redhat·2009-08-06·CVSS 5.9
CVE-2009-3639 [MEDIUM] ProFTPD: Doesn't properly handle NULL character in subjectAltName
ProFTPD: Doesn't properly handle NULL character in subjectAltName
The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, which allows remote attackers to bypass intended client-hostname restrictions via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Red Hat
fetchmail: SSL null terminator bypass
vendor_redhat·2009-08-05·CVSS 5.9
CVE-2009-2666 [MEDIUM] fetchmail: SSL null terminator bypass
fetchmail: SSL null terminator bypass
socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Ubuntu
NSPR update
vendor_ubuntu·2009-08-04·CVSS 9.3
CVE-2009-2404 [CRITICAL] NSPR update
Title: NSPR update
Summary: NSPR update
USN-810-1 fixed vulnerabilities in NSS. This update provides the NSPR
needed to use the new NSS.
Original advisory details:
Moxie Marlinspike discovered that NSS did not properly handle regular
expressions in certificate names. A remote attacker could create a
specially crafted certificate to cause a denial of service (via application
crash) or execute arbitrary code as the user invoking the program.
(CVE-2009-2404)
Moxie Marlinspike and Dan Kaminsky independently discovered that NSS did
not properly handle certificates with NULL characters in the certificate
name. An attacker could exploit this to perform a machine-in-the-middle attack
to view sensitive information or alter encrypted communications.
(CVE-2009-2408)
Dan Kaminsky discovered NSS
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2009-08-04·CVSS 9.3
CVE-2009-2404 [CRITICAL] NSS vulnerabilities
Title: NSS vulnerabilities
Summary: NSS vulnerabilities
Moxie Marlinspike discovered that NSS did not properly handle regular
expressions in certificate names. A remote attacker could create a
specially crafted certificate to cause a denial of service (via application
crash) or execute arbitrary code as the user invoking the program.
(CVE-2009-2404)
Moxie Marlinspike and Dan Kaminsky independently discovered that NSS did
not properly handle certificates with NULL characters in the certificate
name. An attacker could exploit this to perform a machine-in-the-middle attack
to view sensitive information or alter encrypted communications.
(CVE-2009-2408)
Dan Kaminsky discovered NSS would still accept certificates with MD2 hash
signatures. As a result, an attacker could potentially create a
Red Hat
firefox/nss: doesn't handle NULL in Common Name properly
vendor_redhat·2009-07-29·CVSS 5.9
CVE-2009-2408 [MEDIUM] firefox/nss: doesn't handle NULL in Common Name properly
firefox/nss: doesn't handle NULL in Common Name properly
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. NOTE: this was originally reported for Firefox before 3.5.
Debian
CVE-2009-3490: wget - GNU Wget before 1.12 does not properly handle a '\0' character in a domain name ...
vendor_debian·2009·CVSS 5.9
CVE-2009-3490 [MEDIUM] CVE-2009-3490: wget - GNU Wget before 1.12 does not properly handle a '\0' character in a domain name ...
GNU Wget before 1.12 does not properly handle a '\0' character in a domain name in the Common Name field of an X.509 certificate, which allows man-in-the-middle remote attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Scope: local
bookworm: resolved (fixed in 1.12-1)
bullseye: resolved (fixed in 1.12-1)
forky: resolved (fixed in 1.12-1)
sid: resolved (fixed in 1.12-1)
trixie: resolved (fixed in 1.12-1)
Debian
CVE-2009-3942: msmtp - Martin Lambers msmtp before 1.4.19, when OpenSSL is used, does not properly hand...
vendor_debian·2009·CVSS 5.9
CVE-2009-3942 [MEDIUM] CVE-2009-3942: msmtp - Martin Lambers msmtp before 1.4.19, when OpenSSL is used, does not properly hand...
Martin Lambers msmtp before 1.4.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2009-2417: curl - lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does ...
vendor_debian·2009·CVSS 5.9
CVE-2009-2417 [MEDIUM] CVE-2009-2417: curl - lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does ...
lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Scope: local
bookworm: resolved (fixed in 7.19.5-1.1)
bullseye: resolved (fixed in 7.19.5-1.1)
forky: resolved (fixed in 7.19.5-1.1)
sid: resolved (fixed in 7.19.5-1.1)
trixie: resolved (fixed in 7.19.5-1.1)
Debian
CVE-2009-2408: nss - Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Th...
vendor_debian·2009·CVSS 5.9
CVE-2009-2408 [MEDIUM] CVE-2009-2408: nss - Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Th...
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. NOTE: this was originally reported for Firefox before 3.5.
Scope: local
bookworm: resolved (fixed in 3.12.3-1)
bullseye: resolved (fixed in 3.12.3-1)
forky: resolved (fixed in 3.12.3-1)
sid: resolved (fixed in 3.12.3-1)
trixie: resolved (fixed in 3.12.3-1)
Debian
CVE-2009-3767: openldap - libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, ...
vendor_debian·2009·CVSS 5.9
CVE-2009-3767 [MEDIUM] CVE-2009-3767: openldap - libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, ...
libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Scope: local
bookworm: resolved (fixed in 2.4.17-2.1)
bullseye: resolved (fixed in 2.4.17-2.1)
forky: resolved (fixed in 2.4.17-2.1)
sid: resolved (fixed in 2.4.17-2.1)
trixie: resolved (fixed in 2.4.17-2.1)
Debian
CVE-2009-4565: sendmail - sendmail before 8.14.4 does not properly handle a '\0' character in a Common Nam...
vendor_debian·2009·CVSS 5.9
CVE-2009-4565 [MEDIUM] CVE-2009-4565: sendmail - sendmail before 8.14.4 does not properly handle a '\0' character in a Common Nam...
sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Scope: local
bookworm: resolved (fixed in 8.14.3-9.1)
bullseye: resolved (fixed in 8.14.3-9.1)
forky: resolved (fixed in 8.14.3-9.1)
sid: resolved (fixed in 8.14.3-9.1)
trixie: resolved (fixed in 8.14.3-9.1)
Debian
CVE-2009-3639: proftpd-dfsg - The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the...
vendor_debian·2009·CVSS 5.9
CVE-2009-3639 [MEDIUM] CVE-2009-3639: proftpd-dfsg - The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the...
The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, which allows remote attackers to bypass intended client-hostname restrictions via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Scope: local
bookworm: resolved (fixed in 1.3.2a-2)
bullseye: resolved (fixed in 1.3.2a-2)
forky: resolved (fixed in 1.3.2a-2)
sid: resolved (fixed in 1.3.2a-2)
trixie: resolved (fixed in 1.3.2a-2)
Debian
CVE-2009-2666: fetchmail - socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in...
vendor_debian·2009·CVSS 5.9
CVE-2009-2666 [MEDIUM] CVE-2009-2666: fetchmail - socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in...
socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Scope: local
bookworm: resolved (fixed in 6.3.9~rc2-6)
bullseye: resolved (fixed in 6.3.9~rc2-6)
sid: resolved (fixed in 6.3.9~rc2-6)
trixie: resolved (fixed in 6.3.9~rc2-6)
Debian
CVE-2009-3475: opensaml - Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before...
vendor_debian·2009·CVSS 5.9
CVE-2009-3475 [MEDIUM] CVE-2009-3475: opensaml - Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before...
Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before 2.2.1, when using PKIX trust validation, does not properly handle a '\0' character in the subject or subjectAltName fields of a certificate, which allows remote man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Scope: local
bookworm: resolved (fixed in 3.0.0-2)
bullseye: resolved (fixed in 3.0.0-2)
forky: resolved (fixed in 3.0.0-2)
sid: resolved (fixed in 3.0.0-2)
trixie: resolved (fixed in 3.0.0-2)
Debian
CVE-2009-3941: mpop - Martin Lambers mpop before 1.0.19, when OpenSSL is used, does not properly handl...
vendor_debian·2009·CVSS 5.9
CVE-2009-3941 [MEDIUM] CVE-2009-3941: mpop - Martin Lambers mpop before 1.0.19, when OpenSSL is used, does not properly handl...
Martin Lambers mpop before 1.0.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2009-3765: mutt - mutt_ssl.c in mutt 1.5.19 and 1.5.20, when OpenSSL is used, does not properly ha...
vendor_debian·2009·CVSS 5.9
CVE-2009-3765 [MEDIUM] CVE-2009-3765: mutt - mutt_ssl.c in mutt 1.5.19 and 1.5.20, when OpenSSL is used, does not properly ha...
mutt_ssl.c in mutt 1.5.19 and 1.5.20, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2009-2474: litmus - neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '...
vendor_debian·2009·CVSS 5.9
CVE-2009-2474 [MEDIUM] CVE-2009-2474: litmus - neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '...
neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Scope: local
bookworm: resolved (fixed in 0.13-1)
bullseye: resolved (fixed in 0.13-1)
forky: resolved (fixed in 0.13-1)
sid: resolved (fixed in 0.13-1)
trixie: resolved (fixed in 0.13-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3170 firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
bugzilla·2010-09-03·CVSS 5.9
CVE-2010-3170 [MEDIUM] CVE-2010-3170 firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
CVE-2010-3170 firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
Richard Moore and Simon Ward reported flaws in the way browsers such
as Firefox handled wildcard characters in the Common Name field of
a certificate. If an attacker is able to get a carefully-crafted certificate,
signed by a Certificate Authority trusted by Firefox, the attacker could
use the certificate during the man-in-the-middle attack and potentially
confuse Firefox into accepting it by mistake. Different vulnerability than
CVE-2009-2408.
References:
[1] http://www.westpoint.ltd.uk/advisories/wp-10-0001.txt
[2] http://bugs.gentoo.org/show_bug.cgi?id=335731
Discussion:
This will be fixed in NSS 3.12.8
---
Mozilla has assigned CVE-2010-3170 identifier to this issue.
Mozilla upstream bug:
[3]
Bugzilla
CVE-2010-5076 Qt: QSslSocket incorrect handling of IP wildcards in certificate Common Name
bugzilla·2010-09-03·CVSS 5.9
CVE-2010-5076 [MEDIUM] CVE-2010-5076 Qt: QSslSocket incorrect handling of IP wildcards in certificate Common Name
CVE-2010-5076 Qt: QSslSocket incorrect handling of IP wildcards in certificate Common Name
Richard Moore and Simon Ward reported flaw in the way Qt software toolkit
handled wildcard characters in the Common Name field of a x509v3 digital
certificate. If an attacker is able to get a carefully-crafted certificate,
signed by a Certificate Authority trusted by Konqueror / Arora web browsers,
the attacker could use the certificate during the man-in-the-middle attack
and potentially confuse Konqueror / Arora into accepting it by mistake.
Different vulnerability than CVE-2009-2408.
References:
[1] http://www.westpoint.ltd.uk/advisories/wp-10-0001.txt
[2] http://bugs.gentoo.org/show_bug.cgi?id=335730
Discussion:
Upstream commit addressing this issue:
http://qt.gitorious.org/qt/qt/commit/846f1b
Bugzilla
CVE-2010-2074 w3m: doesn't handle NULL in Common Name properly
bugzilla·2010-06-16·CVSS 5.9
CVE-2010-2074 [MEDIUM] CVE-2010-2074 w3m: doesn't handle NULL in Common Name properly
CVE-2010-2074 w3m: doesn't handle NULL in Common Name properly
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-2074 to
the following vulnerability:
Name: CVE-2010-2074
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2074
Assigned: 20100525
Reference: MLIST:[oss-security] 20100614 CVE Request: w3m does not check null bytes CN/subjAltName
Reference: URL: http://www.openwall.com/lists/oss-security/2010/06/14/4
Reference: BID:40837
Reference: URL: http://www.securityfocus.com/bid/40837
Reference: SECUNIA:40134
Reference: URL: http://secunia.com/advisories/40134
Reference: VUPEN:ADV-2010-1467
Reference: URL: http://www.vupen.com/english/advisories/2010/1467
istream.c in w3m 0.5.2 and possibly other versions, when
ssl_verify_server is enabled, does not properl
Bugzilla
CVE-2010-1192 CVE-2010-1194 libESMTP: Multiple certificate validation flaws
bugzilla·2010-03-09·CVSS 5.9
CVE-2010-1192 [MEDIUM] CVE-2010-1192 CVE-2010-1194 libESMTP: Multiple certificate validation flaws
CVE-2010-1192 CVE-2010-1194 libESMTP: Multiple certificate validation flaws
Issue 1,
Kees Cook from Ubuntu Security Team pointed out:
[1] http://www.openwall.com/lists/oss-security/2010/03/03/6
that libesmtp is prone to similar attack as CVE-2009-2408
for Firefox / NSS was:
[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2408
[3] https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-2408
Dan Kaminsky in his research paper:
[4] http://ioactive.com/pdfs/PKILayerCake.pdf
details inconsistencies in the interpretation of subject
x509 names in certificates. Specifically "issue 2, attack 2c"
regarding NULL terminators in a Common Name field. An attacker
could create a malicious certificate containing a NULL,
which, if they were able to get it signed, could confuse
a client into acc
Bugzilla
CVE-2009-4565 sendmail: incorrect verification of SSL certificate with NUL in name
bugzilla·2010-01-05·CVSS 5.9
CVE-2009-4565 [MEDIUM] CVE-2009-4565 sendmail: incorrect verification of SSL certificate with NUL in name
CVE-2009-4565 sendmail: incorrect verification of SSL certificate with NUL in name
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-4565 to the following vulnerability:
sendmail before 8.14.4 does not properly handle a '\0' character in a
Common Name (CN) field of an X.509 certificate, which (1) allows
man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers
via a crafted server certificate issued by a legitimate Certification
Authority, and (2) allows remote attackers to bypass intended access
restrictions via a crafted client certificate issued by a legitimate
Certification Authority, a related issue to CVE-2009-2408.
References:
http://www.sendmail.org/releases/8.14.4
http://www.securityfocus.com/bid/37543
http://secunia.com/advisories/37998
http://ww
Bugzilla
CVE-2009-4034 postgresql: incorrect verification of SSL certificates with NUL in name
bugzilla·2009-12-15·CVSS 5.9
CVE-2009-4034 [MEDIUM] CVE-2009-4034 postgresql: incorrect verification of SSL certificates with NUL in name
CVE-2009-4034 postgresql: incorrect verification of SSL certificates with NUL in name
A CVE-2009-2408-like flaw was found in the way PostgreSQL handled CommonNames with embedded NUL character (\0) in SSL certificates. An attacker able to get a specially-crafted certificate signed by the CA trusted by PostgreSQL client or server could use this flaw to perform a MITM attack against the client, or authenticate as different user when client certificate authentication was configured on the server.
Description from the upstream security page:
http://www.postgresql.org/support/security.html
NULL Bytes in SSL Certificates can be used to falsify client or server
authentication. This only affects users who have SSL enabled, perform
certificate name validation or client certificate authentication
Bugzilla
CVE-2009-3942 msmtp SSL NULL prefix flaw
bugzilla·2009-11-16·CVSS 5.9
CVE-2009-3942 [MEDIUM] CVE-2009-3942 msmtp SSL NULL prefix flaw
CVE-2009-3942 msmtp SSL NULL prefix flaw
Martin Lambers msmtp before 1.4.19, when OpenSSL is used, does not
properly handle a '\0' character in a domain name in the (1) subject's
Common Name or (2) Subject Alternative Name field of an X.509
certificate, which allows man-in-the-middle attackers to spoof
arbitrary SSL servers via a crafted certificate issued by a legitimate
Certification Authority, a related issue to CVE-2009-2408.
Reference: CONFIRM:http://msmtp.sourceforge.net/news.html
Reference: URL:http://secunia.com/advisories/37321
Reference: URL:http://www.vupen.com/english/advisories/2009/3224
Discussion:
Created msmtp tracking bugs for this issue
CVE-2009-3942 Affects: F10 [bug #537933]
CVE-2009-3942 Affects: F11 [bug #537934]
CVE-2009-3942 Affects: F12 [bug #537935]
CVE-2009-
Bugzilla
CVE-2009-3941 mpop NULL character certificate flaw
bugzilla·2009-11-16·CVSS 5.9
CVE-2009-3941 [MEDIUM] CVE-2009-3941 mpop NULL character certificate flaw
CVE-2009-3941 mpop NULL character certificate flaw
Martin Lambers mpop before 1.0.19, when OpenSSL is used, does not
properly handle a '\0' character in a domain name in the (1) subject's
Common Name or (2) Subject Alternative Name field of an X.509
certificate, which allows man-in-the-middle attackers to spoof
arbitrary SSL servers via a crafted certificate issued by a legitimate
Certification Authority, a related issue to CVE-2009-2408.
Reference: CONFIRM:http://mpop.sourceforge.net/news.html
Reference: URL:http://secunia.com/advisories/37312
Reference: URL:http://www.vupen.com/english/advisories/2009/3225
Discussion:
Created mpop tracking bugs for this issue
CVE-2009-3941 Affects: F10 [bug #537928]
CVE-2009-3941 Affects: F11 [bug #537929]
CVE-2009-3941 Affects: F12 [bug #537930]
CV
Bugzilla
CVE-2009-3765 mutt: Doesn't properly handle NULL character in subject Common Name
bugzilla·2009-10-24·CVSS 5.9
CVE-2009-3765 [MEDIUM] CVE-2009-3765 mutt: Doesn't properly handle NULL character in subject Common Name
CVE-2009-3765 mutt: Doesn't properly handle NULL character in subject Common Name
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3765 to
the following vulnerability:
mutt_ssl.c in mutt 1.5.19 and 1.5.20, when OpenSSL is used, does not
properly handle a '\0' character in a domain name in the subject's
Common Name (CN) field of an X.509 certificate, which allows
man-in-the-middle attackers to spoof arbitrary SSL servers via a
crafted certificate issued by a legitimate Certification Authority, a
related issue to CVE-2009-2408.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3765
http://marc.info/?l=oss-security&m=125198917018936&w=2
http://marc.info/?l=oss-security&m=125369675820512&w=2
http://lists.opensuse.org/opensuse-security-announce/2009-10/ms
Bugzilla
CVE-2009-3639 ProFTPD: Doesn't properly handle NULL character in subjectAltName
bugzilla·2009-10-24·CVSS 5.9
CVE-2009-3639 [MEDIUM] CVE-2009-3639 ProFTPD: Doesn't properly handle NULL character in subjectAltName
CVE-2009-3639 ProFTPD: Doesn't properly handle NULL character in subjectAltName
mod_tls.c in ProFTPD 1.3.2a does not properly handle a '\0' character
in a domain name in the subject's alternative name (subjectAltName)
field of an X.509 certificate, which allows man-in-the-middle attackers
to spoof arbitrary SSL servers via a crafted certificate issued by
a legitimate Certification Authority, a related issue to CVE-2009-2408.
Upstream bug report:
http://bugs.proftpd.org/show_bug.cgi?id=3275
Upstream patch:
http://bugs.proftpd.org/attachment.cgi?id=3096
Discussion:
This issue affects the versions of the ProFTPD package, as shipped
with Fedora releases of 10 and 11 (proftpd-1.3.2a-5.fc{10,11}),
and as shipped within Extra Packages for Enterprise Linux 4 and 5
(EPEL-4, EPEL-5) projects (p
Bugzilla
CVE-2009-3767 OpenLDAP: Doesn't properly handle NULL character in subject Common Name
bugzilla·2009-10-24·CVSS 5.9
CVE-2009-3767 [MEDIUM] CVE-2009-3767 OpenLDAP: Doesn't properly handle NULL character in subject Common Name
CVE-2009-3767 OpenLDAP: Doesn't properly handle NULL character in subject Common Name
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3767 to
the following vulnerability:
libraries/libldap/tls_o.c in OpenLDAP, when OpenSSL is used, does not
properly handle a '\0' character in a domain name in the subject's
Common Name (CN) field of an X.509 certificate, which allows
man-in-the-middle attackers to spoof arbitrary SSL servers via a
crafted certificate issued by a legitimate Certification Authority, a
related issue to CVE-2009-2408.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3767
http://marc.info/?l=oss-security&m=125198917018936&w=2
http://marc.info/?l=oss-security&m=125369675820512&w=2
http://lists.opensuse.org/opensuse-security-announce/2009-
Bugzilla
CVE-2009-3291 php: openssl extension: Incorrect verification of SSL certificate with NUL in name
bugzilla·2009-09-18·CVSS 5.9
CVE-2009-3291 [MEDIUM] CVE-2009-3291 php: openssl extension: Incorrect verification of SSL certificate with NUL in name
CVE-2009-3291 php: openssl extension: Incorrect verification of SSL certificate with NUL in name
A method to bypass SSL certificate name vs. host name verification via NUL
('\0') character embedded in X509 certificate's CommonName or subjectAltName
was presented at Black Hat USA 2009:
http://www.blackhat.com/html/bh-usa-09/bh-usa-09-archives.html#Marlinspike
This issue was originally reported for Firefox / NSS, but it affects PHP's
php_openssl_apply_verification_policy() too.
References:
http://www.php.net/ChangeLog-5.php
Upstream patch:
http://svn.php.net/viewvc?view=revision&revision=288329
Discussion:
Created attachment 361656
Local copy of upstream PHP-5.2.11 php_openssl_apply_verification_policy patch
---
This issue affects the versions of php package, as shipped with Red Hat
Bugzilla
CVE-2009-2702 kdelibs: kssl incorrect verification of SSL certificate with NUL in subjectAltName
bugzilla·2009-09-01·CVSS 7.5
CVE-2009-2702 [HIGH] CVE-2009-2702 kdelibs: kssl incorrect verification of SSL certificate with NUL in subjectAltName
CVE-2009-2702 kdelibs: kssl incorrect verification of SSL certificate with NUL in subjectAltName
A method to bypass SSL certificate name vs. host name verification via NUL
('\0') character embedded in X509 certificate's CommonName or subjectAltName
was presented at Black Hat USA 2009:
http://www.blackhat.com/html/bh-usa-09/bh-usa-09-archives.html#Marlinspike
Similar issues affects kdelibs' kssl. Problem only exists in handling of subjectAltNames, CommonNames with embedded NUL chars are handled correctly.
According to Thiago Macieira (maintainer of KDE's and Qt's SSL code), kssl is no longer used in current KDE4 versions, Qt's SSL code is used instead (which is affected by similar problem, see bug #520435).
Problem affects kdelibs 3.5.4 shipped in Red Hat Enterprise Linux 5. Versions i
Bugzilla
CVE-2009-2474 neon: Improper verification of x509v3 certificate with NULL (zero) byte in certain fields
bugzilla·2009-08-19·CVSS 5.9
CVE-2009-2474 [MEDIUM] CVE-2009-2474 neon: Improper verification of x509v3 certificate with NULL (zero) byte in certain fields
CVE-2009-2474 neon: Improper verification of x509v3 certificate with NULL (zero) byte in certain fields
A method to bypass SSL certificate name vs. host name verification via NUL
('\0') character embedded in X509 certificate's CommonName or subjectAltName
was presented at Black Hat USA 2009:
http://www.blackhat.com/html/bh-usa-09/bh-usa-09-archives.html#Marlinspike
References:
[1] http://lists.manyfish.co.uk/pipermail/neon/2009-August/001044.html
[2] http://lists.manyfish.co.uk/pipermail/neon/2009-August/001046.html
More information from Joe Orton about vulnerable Neon versions:
All versions of neon versions up to 0.28.5 inclusive are vulnerable to
this issue, where neon is built with SSL support using OpenSSL.
All versions of neon older than 0.28.6 are affected, where linked
against
Bugzilla
CVE-2009-2666 fetchmail: SSL null terminator bypass
bugzilla·2009-08-05·CVSS 5.9
CVE-2009-2666 [MEDIUM] CVE-2009-2666 fetchmail: SSL null terminator bypass
CVE-2009-2666 fetchmail: SSL null terminator bypass
Fetchmail suffers from a similar NULL terminator bypass in how it handles SSL certificates, as demonstrated with CVE-2009-2408.
The upstream svn repository [1] has been updated with a currently-untested patch (revision 5389), which I will attach in a moment.
[1] http://mknod.org/svn/fetchmail/branches/BRANCH_6-3/
Discussion:
Created attachment 356415
upstream patch (r5389) to correct the issue (untested)
---
Upstream released version 6.3.11 to address this flaw, upstream advisory:
http://www.fetchmail.info/fetchmail-SA-2009-01.txt
---
fetchmail-6.3.8-9.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/fetchmail-6.3.8-9.fc10
---
fetchmail-6.3.9-5.fc11 has been submitted as an update for
Bugzilla
differences in handling of SSL Common Names (Kaminsky)
bugzilla·2009-07-08
[MEDIUM] differences in handling of SSL Common Names (Kaminsky)
differences in handling of SSL Common Names (Kaminsky)
In his upcoming Blackhat paper and presentation Dan Kaminsky
highlights some more issues he has found relating to SSL hash
collisions and related vulnerabilities.
This issue is about how Common Names are checked for validity by applications. For example if a server presents a certificate with two CN entries, how does the app validate those. Does it use the first one, the last one, or all of them?
It turns out that OpenSSL applications do things in different ways. However as the research continued it was noted that the general rule is that a certificate authority must validate all the CN in a certificate they sign. So it's not the case that you could sneak a certificate request past a CA with a legitimate and malicious CN in such a w
Bugzilla
CVE-2009-2408 firefox/nss: doesn't handle NULL in Common Name properly
bugzilla·2009-07-08·CVSS 5.9
CVE-2009-2408 [MEDIUM] CVE-2009-2408 firefox/nss: doesn't handle NULL in Common Name properly
CVE-2009-2408 firefox/nss: doesn't handle NULL in Common Name properly
In his upcoming Blackhat paper and presentation Dan Kaminsky
highlights some more issues he has found relating to SSL hash
collisions and related vulnerabilities.
His second issue is all about inconsistencies in the interpretation of subject
x509 names in certificates. Specifically "issue 2, attack 2c" regarding NULL terminators in a Common Name field. An attacker could create a malicious certificate containing a NULL, which, if they were able to get it signed, could confuse a client into accepting it by mistake.
According to the paper this is said to affect Firefox.
Discussion:
This issue is fixed in upstream NSS 3.12.3 by the following bzs:
Improper character escaping and unescaping in alg1485.c & secname.c
http
CWE
Improper Validation of Certificate with Host Mismatch
mitre_cwe
CWE-297 Improper Validation of Certificate with Host Mismatch
CWE-297: Improper Validation of Certificate with Host Mismatch
The product communicates with a host that provides a certificate, but the product does not properly ensure that the certificate is actually associated with that host.
Even if a certificate is well-formed, signed, and follows the chain of trust, it may simply be a valid certificate for a different site than the site that the product is interacting with. If the certificate's host-specific data is not properly checked - such as the Common Name (CN) in the Subject or the Subject Alternative Name (SAN) extension of an X.509 certificate - it may be possible for a redirection or spoofing attack to allow a malicious host with a valid certificate to provide data, impersonating a trusted host. In order to ensure data integrity, the cer
CWE
Improper Certificate Validation
mitre_cwe
CWE-295 Improper Certificate Validation
CWE-295: Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
Background: A certificate is a token that associates an identity (principal) to a cryptographic key. Certificates can be used to check if a public key belongs to the assumed owner.
Modes of Introduction:
Phase: Architecture and Design
Phase: Implementation
Note: REALIZATION: This weakness is caused during implementation of an architectural security tactic.
Phase: Implementation
Note: When the product uses certificate pinning, the developer might not properly validate all relevant components of the certificate before pinning the certificate. This can make it difficult or expensive to test after the pinning is complete.
Common Consequences:
Scope: Integrity, Authentication. Im
http://isc.sans.org/diary.html?storyid=7003http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.htmlhttp://marc.info/?l=oss-security&m=125198917018936&w=2http://osvdb.org/56723http://secunia.com/advisories/36088http://secunia.com/advisories/36125http://secunia.com/advisories/36139http://secunia.com/advisories/36157http://secunia.com/advisories/36434http://secunia.com/advisories/36669http://secunia.com/advisories/37098http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021030.1-1http://www.debian.org/security/2009/dsa-1874http://www.mandriva.com/security/advisories?name=MDVSA-2009:197http://www.mandriva.com/security/advisories?name=MDVSA-2009:216http://www.mandriva.com/security/advisories?name=MDVSA-2009:217http://www.mozilla.org/security/announce/2009/mfsa2009-42.htmlhttp://www.novell.com/linux/security/advisories/2009_48_firefox.htmlhttp://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_m.c.diff?r1=1.8&r2=1.11&f=hhttp://www.redhat.com/support/errata/RHSA-2009-1207.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1432.htmlhttp://www.securitytracker.com/id?1022632http://www.ubuntu.com/usn/usn-810-1http://www.vupen.com/english/advisories/2009/2085http://www.vupen.com/english/advisories/2009/3184http://www.wired.com/threatlevel/2009/07/kaminsky/https://bugzilla.redhat.com/show_bug.cgi?id=510251https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10751https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8458https://usn.ubuntu.com/810-2/http://isc.sans.org/diary.html?storyid=7003http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.htmlhttp://marc.info/?l=oss-security&m=125198917018936&w=2http://osvdb.org/56723http://secunia.com/advisories/36088http://secunia.com/advisories/36125http://secunia.com/advisories/36139http://secunia.com/advisories/36157http://secunia.com/advisories/36434http://secunia.com/advisories/36669http://secunia.com/advisories/37098http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021030.1-1http://www.debian.org/security/2009/dsa-1874http://www.mandriva.com/security/advisories?name=MDVSA-2009:197http://www.mandriva.com/security/advisories?name=MDVSA-2009:216http://www.mandriva.com/security/advisories?name=MDVSA-2009:217http://www.mozilla.org/security/announce/2009/mfsa2009-42.htmlhttp://www.novell.com/linux/security/advisories/2009_48_firefox.htmlhttp://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_m.c.diff?r1=1.8&r2=1.11&f=hhttp://www.redhat.com/support/errata/RHSA-2009-1207.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1432.htmlhttp://www.securitytracker.com/id?1022632http://www.ubuntu.com/usn/usn-810-1http://www.vupen.com/english/advisories/2009/2085http://www.vupen.com/english/advisories/2009/3184http://www.wired.com/threatlevel/2009/07/kaminsky/https://bugzilla.redhat.com/show_bug.cgi?id=510251https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10751https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8458https://usn.ubuntu.com/810-2/
2009-07-30
Published