CVE-2009-2702

EPSS 0.45%

kdelibs - SSL certificate verification weakness

發布日:2009/9/8修改日:2026/3/9
也稱為:DSA-1916-1DEBIAN-CVE-2009-2702

描述

KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

受影響套件(2)

參考連結(5)