[Pkg-openssl-devel] Bug#539449: CVE-2009-2408: vulnerable to null character certificate spoofing

Giuseppe Iuculano giuseppe at iuculano.it
Wed Aug 5 13:32:17 UTC 2009


retitle 539449 CVE-2009-2408: vulnerable to null character certificate spoofing
thanks

Hi,
this issue got a CVE id:

CVE-2009-2408[0]:
| Mozilla Firefox before 3.5 and NSS before 3.12.3 do not properly
| handle a '\0' character in a domain name in the subject's Common Name
| (CN) field of an X.509 certificate, which allows man-in-the-middle
| attackers to spoof arbitrary SSL servers via a crafted certificate
| issued by a legitimate Certification Authority.

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2408
    http://security-tracker.debian.net/tracker/CVE-2009-2408

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 197 bytes
Desc: OpenPGP digital signature
URL: <http://lists.alioth.debian.org/pipermail/pkg-openssl-devel/attachments/20090805/b880cdb7/attachment.pgp>


More information about the Pkg-openssl-devel mailing list