LWN.net Logo

msmtp: X.509 NULL spoofing

Package(s):msmtp CVE #(s):CVE-2009-3942
Created:June 26, 2012 Updated:June 27, 2012
Description: From the CVE entry:

Martin Lambers msmtp before 1.4.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Alerts:
Gentoo 201206-34 2012-06-25

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds