6.8

CVE-2009-2408

Medienbericht

Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. NOTE: this was originally reported for Firefox before 3.5.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MozillaFirefox Version < 3.0.13
MozillaNetwork Security Services Version < 3.12.3
MozillaSeamonkey Version < 1.1.18
MozillaThunderbird Version < 2.0.0.23
OpensuseOpensuse Version >= 10.3 <= 11.1
SuseLinux Enterprise Version10.0 Update-
SuseLinux Enterprise Version11.0 Update-
DebianDebian Linux Version5.0
CanonicalUbuntu Linux Version8.04 SwEdition-
CanonicalUbuntu Linux Version8.10
CanonicalUbuntu Linux Version9.04
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.69% 0.815
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

http://secunia.com/advisories/36088
Vendor Advisory
Broken Link
http://secunia.com/advisories/36125
Vendor Advisory
Broken Link
http://secunia.com/advisories/36139
Vendor Advisory
Broken Link
http://secunia.com/advisories/36157
Vendor Advisory
Broken Link
http://secunia.com/advisories/36434
Vendor Advisory
Broken Link
http://www.securitytracker.com/id?1022632
Third Party Advisory
Broken Link
VDB Entry