7.5
CVSSv2

CVE-2009-2417

Published: 14/08/2009 Updated: 10/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

lib/ssluse.c in cURL and libcurl 7.4 up to and including 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle malicious users to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Vulnerable Product Search on Vulmon Subscribe to Product

curl libcurl 7.4

curl libcurl 7.4.1

curl libcurl 7.7

curl libcurl 7.7.1

curl libcurl 7.7.2

curl libcurl 7.9.3

curl libcurl 7.9.5

curl libcurl 7.10.3

curl libcurl 7.10.4

curl libcurl 7.12.0

curl libcurl 7.17.0

curl libcurl 7.19.2

curl libcurl 7.19.3

curl libcurl 7.13.1

curl libcurl 7.12.3

libcurl libcurl 7.15.1

libcurl libcurl 7.14

curl libcurl 7.15.3

libcurl libcurl 7.13

curl libcurl 7.4.2

curl libcurl 7.5

curl libcurl 7.7.3

curl libcurl 7.8

curl libcurl 7.9.6

curl libcurl 7.9.7

curl libcurl 7.10.5

curl libcurl 7.10.6

curl libcurl 7.17.1

curl libcurl 7.18.0

curl libcurl 7.19.4

curl libcurl 7.19.5

curl libcurl 7.12.2

curl libcurl 7.12.1

curl libcurl 7.15.2

libcurl libcurl 7.14.1

curl libcurl 7.16.3

libcurl libcurl 7.12.1

curl libcurl 7.6

curl libcurl 7.6.1

curl libcurl 7.9.1

curl libcurl 7.9.2

curl libcurl 7.10.1

curl libcurl 7.10.2

curl libcurl 7.11.0

curl libcurl 7.11.1

curl libcurl 7.11.2

curl libcurl 7.19.0

curl libcurl 7.19.1

curl libcurl 7.14

curl libcurl 7.13.2

libcurl libcurl 7.15.3

libcurl libcurl 7.15

libcurl libcurl 7.13.2

libcurl libcurl 7.12.3

curl libcurl 7.15.1

curl libcurl 7.5.1

curl libcurl 7.5.2

curl libcurl 7.8.1

curl libcurl 7.9

curl libcurl 7.9.8

curl libcurl 7.10

curl libcurl 7.10.7

curl libcurl 7.10.8

curl libcurl 7.18.1

curl libcurl 7.18.2

libcurl libcurl 7.12

curl libcurl 7.14.1

curl libcurl 7.12

libcurl libcurl 7.16.3

libcurl libcurl 7.15.2

curl libcurl 7.13

libcurl libcurl 7.13.1

curl libcurl 7.15

libcurl libcurl 7.12.2

Vendor Advisories

Debian Bug report logs - #541991 CVE-2009-2417: OpenSSL NULL Character Spoofing Vulnerability Package: curl; Maintainer for curl is Alessandro Ghedini <ghedo@debianorg>; Source for curl is src:curl (PTS, buildd, popcon) Reported by: Giuseppe Iuculano <giuseppe@iuculanoit> Date: Mon, 17 Aug 2009 08:39:02 UTC Severi ...
Multiple vulnerabilities in curl ...
Scott Cantor discovered that Curl did not correctly handle SSL certificates with zero bytes in the Common Name A remote attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications ...

References

CWE-310http://curl.haxx.se/CVE-2009-2417/curl-7.18.1-CVE-2009-2417.patchhttp://www.vupen.com/english/advisories/2009/2263http://curl.haxx.se/CVE-2009-2417/curl-7.12.1-CVE-2009-2417.patchhttp://curl.haxx.se/docs/adv_20090812.txthttp://curl.haxx.se/CVE-2009-2417/curl-7.16.4-CVE-2009-2417.patchhttp://curl.haxx.se/CVE-2009-2417/curl-7.15.5-CVE-2009-2417.patchhttp://curl.haxx.se/CVE-2009-2417/curl-7.11.0-CVE-2009-2417.patchhttp://curl.haxx.se/CVE-2009-2417/curl-7.19.0-CVE-2009-2417.patchhttp://www.securityfocus.com/bid/36032http://curl.haxx.se/CVE-2009-2417/curl-7.19.5-CVE-2009-2417.patchhttp://curl.haxx.se/CVE-2009-2417/curl-7.10.6-CVE-2009-2417.patchhttp://secunia.com/advisories/36238http://curl.haxx.se/CVE-2009-2417/curl-7.15.1-CVE-2009-2417.patchhttp://secunia.com/advisories/36475http://wiki.rpath.com/Advisories:rPSA-2009-0124http://shibboleth.internet2.edu/secadv/secadv_20090817.txthttp://www.vupen.com/english/advisories/2009/3316http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://secunia.com/advisories/37471http://support.apple.com/kb/HT4077http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlhttp://www.ubuntu.com/usn/USN-1158-1http://secunia.com/advisories/45047https://exchange.xforce.ibmcloud.com/vulnerabilities/52405https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8542https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10114http://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/archive/1/506055/100/0/threadedhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=541991https://nvd.nist.govhttps://usn.ubuntu.com/1158-1/