7.5

CVE-2009-2417

lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CurlLibcurl Version7.4
CurlLibcurl Version7.4.1
CurlLibcurl Version7.4.2
CurlLibcurl Version7.5
CurlLibcurl Version7.5.1
CurlLibcurl Version7.5.2
CurlLibcurl Version7.6
CurlLibcurl Version7.6.1
CurlLibcurl Version7.7
CurlLibcurl Version7.7.1
CurlLibcurl Version7.7.2
CurlLibcurl Version7.7.3
CurlLibcurl Version7.8
CurlLibcurl Version7.8.1
CurlLibcurl Version7.9
CurlLibcurl Version7.9.1
CurlLibcurl Version7.9.2
CurlLibcurl Version7.9.3
CurlLibcurl Version7.9.5
CurlLibcurl Version7.9.6
CurlLibcurl Version7.9.7
CurlLibcurl Version7.9.8
CurlLibcurl Version7.10
CurlLibcurl Version7.10.1
CurlLibcurl Version7.10.2
CurlLibcurl Version7.10.3
CurlLibcurl Version7.10.4
CurlLibcurl Version7.10.5
CurlLibcurl Version7.10.6
CurlLibcurl Version7.10.7
CurlLibcurl Version7.10.8
CurlLibcurl Version7.11.0
CurlLibcurl Version7.11.1
CurlLibcurl Version7.11.2
CurlLibcurl Version7.12
CurlLibcurl Version7.12.0
CurlLibcurl Version7.12.1
CurlLibcurl Version7.12.2
CurlLibcurl Version7.12.3
CurlLibcurl Version7.13
CurlLibcurl Version7.13.1
CurlLibcurl Version7.13.2
CurlLibcurl Version7.14
CurlLibcurl Version7.14.1
CurlLibcurl Version7.15
CurlLibcurl Version7.15.1
CurlLibcurl Version7.15.2
CurlLibcurl Version7.15.3
CurlLibcurl Version7.16.3
CurlLibcurl Version7.17.0
CurlLibcurl Version7.17.1
CurlLibcurl Version7.18.0
CurlLibcurl Version7.18.1
CurlLibcurl Version7.18.2
CurlLibcurl Version7.19.0
CurlLibcurl Version7.19.1
CurlLibcurl Version7.19.2
CurlLibcurl Version7.19.3
CurlLibcurl Version7.19.4
CurlLibcurl Version7.19.5
LibcurlLibcurl Version7.12
LibcurlLibcurl Version7.12.1
LibcurlLibcurl Version7.12.2
LibcurlLibcurl Version7.12.3
LibcurlLibcurl Version7.13
LibcurlLibcurl Version7.13.1
LibcurlLibcurl Version7.13.2
LibcurlLibcurl Version7.14
LibcurlLibcurl Version7.14.1
LibcurlLibcurl Version7.15
LibcurlLibcurl Version7.15.1
LibcurlLibcurl Version7.15.2
LibcurlLibcurl Version7.15.3
LibcurlLibcurl Version7.16.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.6% 0.88
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html
http://support.apple.com/kb/HT4077
http://secunia.com/advisories/37471
http://www.securityfocus.com/archive/1/507985/100/0/threaded
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
http://www.vupen.com/english/advisories/2009/3316
http://curl.haxx.se/CVE-2009-2417/curl-7.10.6-CVE-2009-2417.patch
Patch
http://curl.haxx.se/CVE-2009-2417/curl-7.11.0-CVE-2009-2417.patch
Patch
http://curl.haxx.se/CVE-2009-2417/curl-7.12.1-CVE-2009-2417.patch
Patch
http://curl.haxx.se/CVE-2009-2417/curl-7.15.1-CVE-2009-2417.patch
Patch
http://curl.haxx.se/CVE-2009-2417/curl-7.15.5-CVE-2009-2417.patch
Patch
http://curl.haxx.se/CVE-2009-2417/curl-7.16.4-CVE-2009-2417.patch
Patch
Vendor Advisory
http://curl.haxx.se/CVE-2009-2417/curl-7.18.1-CVE-2009-2417.patch
Patch
http://curl.haxx.se/CVE-2009-2417/curl-7.19.0-CVE-2009-2417.patch
Patch
http://curl.haxx.se/CVE-2009-2417/curl-7.19.5-CVE-2009-2417.patch
Patch
http://curl.haxx.se/docs/adv_20090812.txt
Vendor Advisory
http://secunia.com/advisories/36238
Vendor Advisory
http://secunia.com/advisories/36475
http://secunia.com/advisories/45047
http://shibboleth.internet2.edu/secadv/secadv_20090817.txt
http://wiki.rpath.com/Advisories:rPSA-2009-0124
http://www.securityfocus.com/archive/1/506055/100/0/threaded
http://www.securityfocus.com/bid/36032
http://www.ubuntu.com/usn/USN-1158-1
http://www.vupen.com/english/advisories/2009/2263
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/52405
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10114
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8542