4.3
CVSSv2

CVE-2011-3365

Published: 29/11/2011 Updated: 13/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The KDE SSL Wrapper (KSSL) API in KDE SC 4.6.0 up to and including 4.7.1, and possibly earlier versions, does not use a certain font when rendering certificate fields in a security dialog, which allows remote malicious users to spoof the common name (CN) of a certificate via rich text.

Vulnerable Product Search on Vulmon Subscribe to Product

kde kde sc 4.6.4

kde kde sc 4.7.0

kde kde sc 4.6.1

kde kde sc 4.7.1

kde kde sc 4.6.2

kde kde sc 4.6.3

kde kde sc 4.6.0

kde kde sc 4.6.5

Vendor Advisories

KDE-Libs could improperly display fraudulent security certificates ...