KDE / Konqueror Embedded Common Name证书验证漏洞

漏洞信息详情

KDE / Konqueror Embedded Common Name证书验证漏洞

漏洞简介

Konqueror Embedded和KDE 2.2.2及其更早的版本没有验证X.509证书的Common Name (CN)字段,远程攻击者可能利用该漏洞借助一个man-in-the-middle攻击骗取证书。

漏洞公告

Please see the referenced advisories for more information.
KDE Konqueror Embedded 0.1

KDE KDE 2.2.2

参考网址

来源: REDHAT
名称: RHSA-2003:192
链接:http://www.redhat.com/support/errata/RHSA-2003-192.html

来源: www.kde.org
链接:http://www.kde.org/info/security/advisory-20030602-1.txt

来源: TURBO
名称: TLSA-2003-36
链接:http://www.turbolinux.com/security/TLSA-2003-36.txt

来源: BUGTRAQ
名称: 20030507 Problem: Multiple Web Browsers do not do not validate CN on certificates.
链接:http://www.securityfocus.com/archive/1/320707

来源: REDHAT
名称: RHSA-2003:193
链接:http://www.redhat.com/support/errata/RHSA-2003-193.html

来源: DEBIAN
名称: DSA-361
链接:http://www.debian.org/security/2003/dsa-361

来源: FULLDISC
名称: 20030510 [forward]Apple Safari and Konqueror Embedded Common Name Verification Vulnerability
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2003-May/004983.html

来源: BID
名称: 7520
链接:http://www.securityfocus.com/bid/7520

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享