LWN.net Logo

qt: man-in-the-middle attack

Package(s):qt CVE #(s):CVE-2009-2700
Created:September 3, 2009 Updated:February 3, 2010
Description: From the National Vulnerability Database entry: "src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408."
Alerts:
Debian DSA-1988-1 2010-02-02
SuSE SUSE-SR:2009:019 2009-11-24
Ubuntu USN-829-1 2009-09-10
Fedora FEDORA-2009-9232 2009-09-03
Mandriva MDVSA-2009:225 2009-09-08
Fedora FEDORA-2009-9231 2009-09-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds