6.8
CVSSv2

CVE-2014-3604

Published: 25/10/2014 Updated: 05/01/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Certificates.java in Not Yet Commons SSL prior to 0.3.15 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle malicious users to spoof SSL servers via an arbitrary valid certificate.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

not yet commons ssl project not yet commons ssl

Vendor Advisories

Debian Bug report logs - #759526 not-yet-commons-ssl: CVE-2014-3604 Package: not-yet-commons-ssl; Maintainer for not-yet-commons-ssl is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Thu, 28 Aug 2014 06:18:02 UTC Severity: grave Tags: sec ...
It was discovered that the implementation used by the Not Yet Commons SSL project to check that the server hostname matches the domain name in the subject's CN field was flawed This could be exploited by a man-in-the-middle attacker by spoofing a valid certificate using a specially crafted subject ...