[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-2474Date: (C)2009-08-21   (M)2024-02-22


neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.8
Exploit Score: 8.6
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: NONE
  
Reference:
BID-36079
SECUNIA-36371
SECUNIA-36799
ADV-2009-2341
APPLE-SA-2010-11-10-1
FEDORA-2009-8794
FEDORA-2009-8815
MDVSA-2009:221
USN-835-1
http://lists.manyfish.co.uk/pipermail/neon/2009-August/001046.html
http://lists.manyfish.co.uk/pipermail/neon/2009-August/001044.html
http://support.apple.com/kb/HT4435
oval:org.mitre.oval:def:11721

CPE    8
cpe:/o:apple:mac_os_x
cpe:/o:fedoraproject:fedora:10
cpe:/o:fedoraproject:fedora:11
cpe:/a:webdav:neon
...
CWE    1
CWE-326
OVAL    10
oval:org.secpod.oval:def:4723
oval:org.secpod.oval:def:202184
oval:org.secpod.oval:def:300448
oval:org.secpod.oval:def:4729
...

© SecPod Technologies