CVE-2009-3490
published 2009-09-30CVE-2009-3490: GNU Wget before 1.12 does not properly handle a '\0' character in a domain name in the Common Name field of an X.509 certificate, which allows…
PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.52%
87.8th percentile
GNU Wget before 1.12 does not properly handle a '\0' character in a domain name in the Common Name field of an X.509 certificate, which allows man-in-the-middle remote attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wget | < wget 1.12-1 (bookworm) | wget 1.12-1 (bookworm) |
| gnu | wget | <= 1.11.4 | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | >= 0 < 1.12-1 | 1.12-1 |
| gnu | wget | >= 0 < 1.12-1 | 1.12-1 |
| gnu | wget | >= 0 < 1.12-1 | 1.12-1 |
| gnu | wget | >= 0 < 1.12-1 | 1.12-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Wget vulnerability
vendor_ubuntu·2009-10-06
CVE-2009-3490 Wget vulnerability
Title: Wget vulnerability
Summary: Wget vulnerability
It was discovered that Wget did not correctly handle SSL certificates with
zero bytes in the Common Name. A remote attacker could exploit this to
perform a machine-in-the-middle attack to view sensitive information or alter
encrypted communications.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
wget: incorrect verification of SSL certificate with NUL in name
vendor_redhat·2009-08-12·CVSS 5.9
CVE-2009-3490 [MEDIUM] wget: incorrect verification of SSL certificate with NUL in name
wget: incorrect verification of SSL certificate with NUL in name
GNU Wget before 1.12 does not properly handle a '\0' character in a domain name in the Common Name field of an X.509 certificate, which allows man-in-the-middle remote attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Debian
CVE-2009-3490: wget - GNU Wget before 1.12 does not properly handle a '\0' character in a domain name ...
vendor_debian·2009·CVSS 5.9
CVE-2009-3490 [MEDIUM] CVE-2009-3490: wget - GNU Wget before 1.12 does not properly handle a '\0' character in a domain name ...
GNU Wget before 1.12 does not properly handle a '\0' character in a domain name in the Common Name field of an X.509 certificate, which allows man-in-the-middle remote attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Scope: local
bookworm: resolved (fixed in 1.12-1)
bullseye: resolved (fixed in 1.12-1)
forky: resolved (fixed in 1.12-1)
sid: resolved (fixed in 1.12-1)
trixie: resolved (fixed in 1.12-1)
GHSA
GHSA-6p5c-44cm-r9m8: GNU Wget before 1
ghsa_unreviewed·2022-05-02·CVSS 5.9
CVE-2009-3490 [MEDIUM] GHSA-6p5c-44cm-r9m8: GNU Wget before 1
GNU Wget before 1.12 does not properly handle a '\0' character in a domain name in the Common Name field of an X.509 certificate, which allows man-in-the-middle remote attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
OSV
CVE-2009-3490: GNU Wget before 1
osv·2009-09-30·CVSS 5.9
CVE-2009-3490 [MEDIUM] CVE-2009-3490: GNU Wget before 1
GNU Wget before 1.12 does not properly handle a '\0' character in a domain name in the Common Name field of an X.509 certificate, which allows man-in-the-middle remote attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-3490 wget: incorrect verification of SSL certificate with NUL in name
bugzilla·2009-10-07·CVSS 6.8
CVE-2009-3490 [MEDIUM] CVE-2009-3490 wget: incorrect verification of SSL certificate with NUL in name
CVE-2009-3490 wget: incorrect verification of SSL certificate with NUL in name
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in all affected branches.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #520454: CVE-2009-3490 wget: incorrect verification of SSL certificate with NUL in name
When creating a Bodhi update request, please include the bug IDs of the respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available and only close this bug once all affected Fedora versions are fixed.
Bodhi update submission link:
https://admin.fedoraproject.org/up
Bugzilla
CVE-2009-3490 wget: incorrect verification of SSL certificate with NUL in name
bugzilla·2009-08-31·CVSS 6.8
CVE-2009-3490 [MEDIUM] CVE-2009-3490 wget: incorrect verification of SSL certificate with NUL in name
CVE-2009-3490 wget: incorrect verification of SSL certificate with NUL in name
A method to bypass SSL certificate name vs. host name verification via NUL
('\0') character embedded in X509 certificate's CommonName or subjectAltName
was presented at Black Hat USA 2009:
http://www.blackhat.com/html/bh-usa-09/bh-usa-09-archives.html#Marlinspike
Similar problem affected wget (from a testing and very quick look at the code, subjectAltNames are not supported, hence only CommonName is a vector).
Upstream bug report:
http://savannah.gnu.org/bugs/?27183 (currently not public)
Contents of upstream bug report, leaked via wget-notify list:
http://addictivecode.org/pipermail/wget-notify/2009-August/001808.html
Upstream fixes:
http://hg.addictivecode.org/wget/mainline/rev/2d8c76a23e7d
http://hg.add
http://addictivecode.org/pipermail/wget-notify/2009-August/001808.htmlhttp://hg.addictivecode.org/wget/mainline/rev/1eab157d3be7http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://marc.info/?l=oss-security&m=125198917018936&w=2http://marc.info/?l=oss-security&m=125369675820512&w=2http://permalink.gmane.org/gmane.comp.web.wget.general/8972http://secunia.com/advisories/36540http://www.securityfocus.com/bid/36205http://www.vupen.com/english/advisories/2009/2498https://bugzilla.redhat.com/show_bug.cgi?id=520454https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11099http://addictivecode.org/pipermail/wget-notify/2009-August/001808.htmlhttp://hg.addictivecode.org/wget/mainline/rev/1eab157d3be7http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://marc.info/?l=oss-security&m=125198917018936&w=2http://marc.info/?l=oss-security&m=125369675820512&w=2http://permalink.gmane.org/gmane.comp.web.wget.general/8972http://secunia.com/advisories/36540http://www.securityfocus.com/bid/36205http://www.vupen.com/english/advisories/2009/2498https://bugzilla.redhat.com/show_bug.cgi?id=520454https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11099
2009-09-30
Published