LWN.net Logo

libneon: man in the middle attack

Package(s):libneon0.27 CVE #(s):CVE-2009-2474
Created:August 25, 2009 Updated:December 4, 2009
Description: From the Mandriva advisory: neon before 0.28.6, when OpenSSL is used, does not properly handle a '\0' (NUL) character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408
Alerts:
Mandriva MDVSA-2009:315 2009-12-04
Ubuntu USN-835-1 2009-09-21
CentOS CESA-2009:1452 2009-09-22
Red Hat RHSA-2009:1452-01 2009-09-21
Mandriva MDVSA-2009:228 2009-09-10
Mandriva MDVSA-2009:221 2009-08-24
CentOS CESA-2009:1452 2009-10-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds