7.5
CVSSv2

CVE-2009-3456

Published: 29/09/2009 Updated: 30/09/2009
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Google Chrome, possibly 3.0.195.21 and previous versions, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle malicious users to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome 1.0.154.53

google chrome 0.2.149.29

google chrome 0.2.149.30

google chrome 1.0.154.43

google chrome 1.0.154.48

google chrome 2.0.172.30

google chrome 0.2.153.1

google chrome 0.3.154.0

google chrome 2.0.172.33

google chrome 0.2.149.27

google chrome 1.0.154.42

google chrome 1.0.154.59

google chrome 1.0.154.65

google chrome 2.0.172.2

google chrome 2.0.156.1

google chrome 2.0.172.27

google chrome 3.0.182.2

google chrome 0.2.152.1

google chrome 2.0.170.0

google chrome 2.0.158.0

google chrome 2.0.159.0

google chrome 2.0.169.0

google chrome 0.4.154.22

google chrome 0.4.154.33

google chrome 2.0.172.28

google chrome 3.0.193.2

google chrome 2.0.157.0

google chrome 2.0.157.2

google chrome 0.3.154.3

google chrome 0.4.154.18

google chrome 1.0.154.52

google chrome 2.0.169.1

google chrome

google chrome 0.4.154.31

google chrome 1.0.154.39

google chrome 1.0.154.36

google chrome 2.0.172.37

google chrome 2.0.172.38

google chrome 2.0.172.8

google chrome 3.0.190.2

google chrome 2.0.172.31

google chrome 1.0.154.46

google chrome 2.0.172