4

CVE-2014-3504

The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheSubversion Version1.4.0
ApacheSubversion Version1.4.1
ApacheSubversion Version1.4.2
ApacheSubversion Version1.4.3
ApacheSubversion Version1.4.4
ApacheSubversion Version1.4.5
ApacheSubversion Version1.4.6
ApacheSubversion Version1.5.0
ApacheSubversion Version1.5.1
ApacheSubversion Version1.5.2
ApacheSubversion Version1.5.3
ApacheSubversion Version1.5.4
ApacheSubversion Version1.5.5
ApacheSubversion Version1.5.6
ApacheSubversion Version1.5.7
ApacheSubversion Version1.5.8
ApacheSubversion Version1.6.0
ApacheSubversion Version1.6.1
ApacheSubversion Version1.6.2
ApacheSubversion Version1.6.3
ApacheSubversion Version1.6.4
ApacheSubversion Version1.6.5
ApacheSubversion Version1.6.6
ApacheSubversion Version1.6.7
ApacheSubversion Version1.6.8
ApacheSubversion Version1.6.9
ApacheSubversion Version1.6.10
ApacheSubversion Version1.6.11
ApacheSubversion Version1.6.12
ApacheSubversion Version1.6.13
ApacheSubversion Version1.6.14
ApacheSubversion Version1.6.15
ApacheSubversion Version1.6.16
ApacheSubversion Version1.6.17
ApacheSubversion Version1.6.18
ApacheSubversion Version1.6.19
ApacheSubversion Version1.6.20
ApacheSubversion Version1.6.21
ApacheSubversion Version1.6.23
ApacheSubversion Version1.7.0
ApacheSubversion Version1.7.1
ApacheSubversion Version1.7.2
ApacheSubversion Version1.7.3
ApacheSubversion Version1.7.4
ApacheSubversion Version1.7.5
ApacheSubversion Version1.7.6
ApacheSubversion Version1.7.7
ApacheSubversion Version1.7.8
ApacheSubversion Version1.7.9
ApacheSubversion Version1.7.10
ApacheSubversion Version1.7.11
ApacheSubversion Version1.7.12
ApacheSubversion Version1.7.13
ApacheSubversion Version1.7.14
ApacheSubversion Version1.7.15
ApacheSubversion Version1.7.16
ApacheSubversion Version1.7.17
ApacheSubversion Version1.8.0
ApacheSubversion Version1.8.1
ApacheSubversion Version1.8.2
ApacheSubversion Version1.8.3
ApacheSubversion Version1.8.4
ApacheSubversion Version1.8.5
ApacheSubversion Version1.8.6
ApacheSubversion Version1.8.7
ApacheSubversion Version1.8.8
ApacheSubversion Version1.8.9
CanonicalUbuntu Linux Version12.04 Update- Editionlts
CanonicalUbuntu Linux Version14.04 SwEditionlts
Serf ProjectSerf Version0.2.0
Serf ProjectSerf Version0.3.0
Serf ProjectSerf Version0.3.1
Serf ProjectSerf Version0.4.0
Serf ProjectSerf Version0.5.0
Serf ProjectSerf Version0.6.0
Serf ProjectSerf Version0.6.1
Serf ProjectSerf Version0.7.0
Serf ProjectSerf Version0.7.1
Serf ProjectSerf Version0.7.2
Serf ProjectSerf Version1.0.0
Serf ProjectSerf Version1.0.1
Serf ProjectSerf Version1.0.2
Serf ProjectSerf Version1.0.3
Serf ProjectSerf Version1.1.0
Serf ProjectSerf Version1.1.1
Serf ProjectSerf Version1.2.0
Serf ProjectSerf Version1.2.1
Serf ProjectSerf Version1.3.0
Serf ProjectSerf Version1.3.1
Serf ProjectSerf Version1.3.2
Serf ProjectSerf Version1.3.3
Serf ProjectSerf Version1.3.4
Serf ProjectSerf Version1.3.5
Serf ProjectSerf Version1.3.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.1% 0.835
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4 4.9 4.9
AV:N/AC:H/Au:N/C:P/I:P/A:N