7.5
CVSSv2

CVE-2009-2702

Published: 08/09/2009 Updated: 19/01/2012
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle malicious users to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Vulnerable Product Search on Vulmon Subscribe to Product

kde kdelibs 4.3

kde kdelibs 3.5.4

kde kdelibs 4.2.4

Vendor Advisories

Debian Bug report logs - #546212 CVE-2009-2702: KDE KSSL NULL Character Certificate Spoofing Vulnerability Package: kdelibs; Maintainer for kdelibs is (unknown); Reported by: Giuseppe Iuculano <giuseppe@iuculanoit> Date: Fri, 11 Sep 2009 17:42:02 UTC Severity: serious Tags: security Fixed in versions kdelibs/4:3510dfs ...
It was discovered that KDE did not properly handle certificates with NULL characters in the Subject Alternative Name field of X509 certificates An attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications ...
Dan Kaminsky and Moxie Marlinspike discovered that kdelibs, core libraries from the official KDE release, does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate C ...