4.3
CVSSv2

CVE-2009-2700

Published: 02/09/2009 Updated: 16/06/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle malicious users to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qt qt 4.7.3

qt qt 4.7.2

qt qt 4.0.0

qt qt 4.7.4

qt qt 4.3.4

qt qt 4.3.5

qt qt 4.5.0

qt qt 4.5.1

qt qt 4.4.2

qt qt 4.1.2

qt qt 4.1.1

qt qt 4.8.2

qt qt 4.7.1

qt qt 4.2.0

qt qt 4.6.0

qt qt 4.6.1

qt qt 4.4.0

qt qt 4.4.3

qt qt 4.2.1

qt qt 4.0.1

qt qt 4.1.3

qt qt 4.8.1

qt qt 4.8.0

qt qt 4.8.3

qt qt 4.5.2

qt qt 4.5.3

qt qt 4.6.3

qt qt 4.6.4

qt qt 4.3.3

qt qt 4.3.2

qt qt 4.3.1

qt qt 4.3.0

qt qt 4.8.4

qt qt 4.7.0

qt qt 4.7.5

qt qt 4.6.2

qt qt 4.4.1

qt qt 4.2.3

qt qt 4.1.5

qt qt 4.1.0

qt qt 4.1.4

Vendor Advisories

It was discovered that Qt did not properly handle certificates with NULL characters in the Subject Alternative Name field of X509 certificates An attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications (CVE-2009-2700) ...
Debian Bug report logs - #545793 CVE-2009-2700: QSslCertificate incorrect verification of SSL certificate with NUL in subjectAltName Package: qt4-x11; Maintainer for qt4-x11 is Debian Qt/KDE Maintainers <debian-qt-kde@listsdebianorg>; Reported by: Giuseppe Iuculano <giuseppe@iuculanoit> Date: Wed, 9 Sep 2009 08:00 ...