LWN.net Logo

firefox: compromise of SSL-protected communication

Package(s):firefox CVE #(s):CVE-2009-2408
Created:August 4, 2009 Updated:October 5, 2010
Description: From the Mozilla advisory: IOActive security researcher Dan Kaminsky reported a mismatch in the treatment of domain names in SSL certificates between SSL clients and the Certificate Authorities (CA) which issue server certificates. In particular, if a malicious person requested a certificate for a host name with an invalid null character in it most CAs would issue the certificate if the requester owned the domain specified after the null, while most SSL clients (browsers) ignored that part of the name and used the unvalidated part in front of the null. This made it possible for attackers to obtain certificates that would function for any site they wished to target. These certificates could be used to intercept and potentially alter encrypted communication between the client and a server such as sensitive bank account transactions.
Alerts:
Debian DSA-2025-1 2010-03-31
Mandriva MDVSA-2010:027 2010-01-27
Mandriva MDVSA-2010:028 2010-01-27
Mandriva MDVSA-2009:203-1 2009-12-04
Mandriva MDVSA-2009:315 2009-12-04
Mandriva MDVSA-2009:201-1 2009-12-04
Mandriva MDVSA-2009:197-3 2009-12-03
Mandriva MDVSA-2009:217-3 2009-12-03
SuSE SUSE-SR:2009:018 2009-11-10
Mandriva MDVSA-2009:203 2009-08-15
Mandriva MDVSA-2009:201 2009-08-12
Red Hat RHSA-2009:1207-01 2009-08-12
Mandriva MDVSA-2009:198 2009-08-07
Mandriva MDVSA-2009:197 2009-08-07
Ubuntu USN-810-2 2009-08-04
Ubuntu USN-810-1 2009-08-04
Red Hat RHSA-2009:1190-01 2009-07-31
Red Hat RHSA-2009:1186-01 2009-07-30
Red Hat RHSA-2009:1184-01 2009-07-30
Fedora FEDORA-2009-8288 2009-08-05
Fedora FEDORA-2009-8288 2009-08-05
Fedora FEDORA-2009-8288 2009-08-05
Fedora FEDORA-2009-8288 2009-08-05
Fedora FEDORA-2009-8288 2009-08-05
Fedora FEDORA-2009-8288 2009-08-05
Fedora FEDORA-2009-8288 2009-08-05
Fedora FEDORA-2009-8288 2009-08-05
Fedora FEDORA-2009-8288 2009-08-05
Fedora FEDORA-2009-8288 2009-08-05
Fedora FEDORA-2009-8288 2009-08-05
Fedora FEDORA-2009-8288 2009-08-05
Fedora FEDORA-2009-8288 2009-08-05
Fedora FEDORA-2009-8288 2009-08-05
Fedora FEDORA-2009-8288 2009-08-05
Fedora FEDORA-2009-8288 2009-08-05
Fedora FEDORA-2009-8279 2009-08-05
Fedora FEDORA-2009-8279 2009-08-05
Fedora FEDORA-2009-8288 2009-08-05
Slackware SSA:2009-215-01 2009-08-04
Mandriva MDVSA-2009:288 2009-10-23

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds