|
|
| |
|
| |
kdelibs: certificate spoofing
| Package(s): | kdelibs |
CVE #(s): | CVE-2011-3365
CVE-2011-3366
|
| Created: | October 11, 2011 |
Updated: | November 10, 2011 |
| Description: |
From the KDE advisory:
When displaying a security dialog with a certificate, KSSL does not properly force its QLabels to use QLabel::PlainText. As a result, if given a certificate containing rich text in its fields, it will render the rich text.
Specifically, a certificate containing a common name (CN) that has a table element will cause the second line of the table to be displayed. This can allow spoofing of the certificate's common name.
|
| Alerts: |
|
( Log in to post comments)
|
|
|