|
|
Log in / Subscribe / Register

firefox: compromise of SSL-protected communication

Package(s):firefox CVE #(s):CVE-2009-2408
Created:August 4, 2009 Updated:October 5, 2010
Description: From the Mozilla advisory: IOActive security researcher Dan Kaminsky reported a mismatch in the treatment of domain names in SSL certificates between SSL clients and the Certificate Authorities (CA) which issue server certificates. In particular, if a malicious person requested a certificate for a host name with an invalid null character in it most CAs would issue the certificate if the requester owned the domain specified after the null, while most SSL clients (browsers) ignored that part of the name and used the unvalidated part in front of the null. This made it possible for attackers to obtain certificates that would function for any site they wished to target. These certificates could be used to intercept and potentially alter encrypted communication between the client and a server such as sensitive bank account transactions.
Alerts:
Mandriva MDVSA-2014:014 php 2014-01-21
Gentoo 201301-01 firefox 2013-01-07
Debian DSA-2025-1 icedove 2010-03-31
Mandriva MDVSA-2010:027 kdelibs4 2010-01-27
Mandriva MDVSA-2010:028 kdelibs4 2010-01-27
Mandriva MDVSA-2009:203-1 curl 2009-12-04
Mandriva MDVSA-2009:315 libneon 2009-12-04
Mandriva MDVSA-2009:201-1 fetchmail 2009-12-04
Mandriva MDVSA-2009:197-3 nss 2009-12-03
Mandriva MDVSA-2009:217-3 mozilla-thunderbird 2009-12-03
SuSE SUSE-SR:2009:018 cyrus-imapd, neon/libneon, freeradius, strongswan, openldap2, apache2-mod_jk, expat, xpdf, mozilla-nspr 2009-11-10
Mandriva MDVSA-2009:203 curl 2009-08-15
Mandriva MDVSA-2009:201 fetchmail 2009-08-12
Red Hat RHSA-2009:1207-01 nspr nss 2009-08-12
Mandriva MDVSA-2009:198 firefox 2009-08-07
Mandriva MDVSA-2009:197 nss 2009-08-07
Ubuntu USN-810-2 nspr 2009-08-04
Ubuntu USN-810-1 nss 2009-08-04
Red Hat RHSA-2009:1190-01 nspr, nss 2009-07-31
Red Hat RHSA-2009:1186-01 nspr, nss 2009-07-30
Red Hat RHSA-2009:1184-01 nspr, nss 2009-07-30
Fedora FEDORA-2009-8288 ruby-gnome2 2009-08-05
Fedora FEDORA-2009-8288 xulrunner 2009-08-05
Fedora FEDORA-2009-8288 yelp 2009-08-05
Fedora FEDORA-2009-8288 perl-Gtk2-MozEmbed 2009-08-05
Fedora FEDORA-2009-8288 pcmanx-gtk2 2009-08-05
Fedora FEDORA-2009-8288 mugshot 2009-08-05
Fedora FEDORA-2009-8288 mozvoikko 2009-08-05
Fedora FEDORA-2009-8288 Miro 2009-08-05
Fedora FEDORA-2009-8288 kazehakase 2009-08-05
Fedora FEDORA-2009-8288 google-gadgets 2009-08-05
Fedora FEDORA-2009-8288 gnome-web-photo 2009-08-05
Fedora FEDORA-2009-8288 gnome-python2-extras 2009-08-05
Fedora FEDORA-2009-8288 gecko-sharp2 2009-08-05
Fedora FEDORA-2009-8288 galeon 2009-08-05
Fedora FEDORA-2009-8288 firefox 2009-08-05
Fedora FEDORA-2009-8288 evolution-rss 2009-08-05
Fedora FEDORA-2009-8279 chmsee 2009-08-05
Fedora FEDORA-2009-8279 blam 2009-08-05
Fedora FEDORA-2009-8288 blam 2009-08-05
Slackware SSA:2009-215-01 mozilla-firefox 2009-08-04
Mandriva MDVSA-2009:288 proftpd 2009-10-23

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds