6.8

CVE-2010-1194

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Stafford.UklinuxLibesmtp Version0.1 Update-
Stafford.UklinuxLibesmtp Version0.1 Updatea
Stafford.UklinuxLibesmtp Version0.2
Stafford.UklinuxLibesmtp Version0.3
Stafford.UklinuxLibesmtp Version0.4
Stafford.UklinuxLibesmtp Version0.5
Stafford.UklinuxLibesmtp Version0.6
Stafford.UklinuxLibesmtp Version0.6 Updatea
Stafford.UklinuxLibesmtp Version0.6.1
Stafford.UklinuxLibesmtp Version0.7.0
Stafford.UklinuxLibesmtp Version0.7.1
Stafford.UklinuxLibesmtp Version0.8.0
Stafford.UklinuxLibesmtp Version0.8.1
Stafford.UklinuxLibesmtp Version0.8.2
Stafford.UklinuxLibesmtp Version0.8.3
Stafford.UklinuxLibesmtp Version0.8.4
Stafford.UklinuxLibesmtp Version0.8.5
Stafford.UklinuxLibesmtp Version0.8.6
Stafford.UklinuxLibesmtp Version0.8.7
Stafford.UklinuxLibesmtp Version0.8.8
Stafford.UklinuxLibesmtp Version0.8.9
Stafford.UklinuxLibesmtp Version0.8.10
Stafford.UklinuxLibesmtp Version0.8.10 Updatep1
Stafford.UklinuxLibesmtp Version0.8.11
Stafford.UklinuxLibesmtp Version0.8.12
Stafford.UklinuxLibesmtp Version1.0
Stafford.UklinuxLibesmtp Version1.0 Updaterc1
Stafford.UklinuxLibesmtp Version1.0.1
Stafford.UklinuxLibesmtp Version1.0.2
Stafford.UklinuxLibesmtp Version1.0.3
Stafford.UklinuxLibesmtp Version1.0.3 Updater1
Stafford.UklinuxLibesmtp Version1.0.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.603
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.