5.8
CVSSv2

CVE-2010-3900

Published: 14/10/2010 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Midori prior to 0.2.5, when WebKitGTK+ prior to 1.1.14 or LibSoup prior to 2.29.91 is used, does not verify X.509 certificates, which allows man-in-the-middle malicious users to spoof arbitrary https web sites via a crafted server certificate, a related issue to CVE-2010-3312.

Vulnerable Product Search on Vulmon Subscribe to Product

christian dywan midori 0.2.3

christian dywan midori 0.2.2

christian dywan midori 0.1.10

christian dywan midori 0.2.0

christian dywan midori

christian dywan midori 0.2.1

Vendor Advisories

Debian Bug report logs - #607497 midori: Loads HTTPS with SSL errors without any notice Package: midori; Maintainer for midori is Dominik George <natureshadow@debianorg>; Source for midori is src:midori (PTS, buildd, popcon) Reported by: Witold Baryluk <baryluk@smpifujedupl> Date: Sun, 19 Dec 2010 03:09:01 UTC ...
Debian Bug report logs - #672880 CVE-2012-2132: does not indicate whether or not an SSL certificate is valid Package: midori; Maintainer for midori is Dominik George <natureshadow@debianorg>; Source for midori is src:midori (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: Mon, 14 May 2012 12:39:02 ...