6.8
CVSSv2

CVE-2010-1194

Published: 31/03/2010 Updated: 22/05/2010
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote malicious users to spoof trusted certificates via a crafted subjectAltName.

Vulnerable Product Search on Vulmon Subscribe to Product

stafford.uklinux libesmtp 1.0.1

stafford.uklinux libesmtp 1.0.2

stafford.uklinux libesmtp 0.8.10

stafford.uklinux libesmtp 0.8.9

stafford.uklinux libesmtp 0.8.2

stafford.uklinux libesmtp 0.8.0

stafford.uklinux libesmtp 0.6

stafford.uklinux libesmtp 0.3

stafford.uklinux libesmtp 0.1

stafford.uklinux libesmtp 1.0.3

stafford.uklinux libesmtp 1.0.4

stafford.uklinux libesmtp 0.8.12

stafford.uklinux libesmtp 0.8.6

stafford.uklinux libesmtp 0.8.5

stafford.uklinux libesmtp 0.7.1

stafford.uklinux libesmtp 0.2

stafford.uklinux libesmtp 0.8.11

stafford.uklinux libesmtp 0.8.3

stafford.uklinux libesmtp 0.8.4

stafford.uklinux libesmtp 0.5

stafford.uklinux libesmtp 0.6.1

stafford.uklinux libesmtp 1.0

stafford.uklinux libesmtp 0.8.7

stafford.uklinux libesmtp 0.8.8

stafford.uklinux libesmtp 0.7.0

stafford.uklinux libesmtp 0.8.1

stafford.uklinux libesmtp 0.4