firefox: compromise of SSL-protected communication
| Package(s): | firefox |
CVE #(s): | CVE-2009-2408
|
| Created: | August 4, 2009 |
Updated: | October 5, 2010 |
| Description: |
From the Mozilla
advisory: IOActive security researcher Dan Kaminsky reported a mismatch
in the treatment of domain names in SSL certificates between SSL clients
and the Certificate Authorities (CA) which issue server certificates. In
particular, if a malicious person requested a certificate for a host name
with an invalid null character in it most CAs would issue the certificate
if the requester owned the domain specified after the null, while most SSL
clients (browsers) ignored that part of the name and used the unvalidated
part in front of the null. This made it possible for attackers to obtain
certificates that would function for any site they wished to target. These
certificates could be used to intercept and potentially alter encrypted
communication between the client and a server such as sensitive bank
account transactions. |
| Alerts: |
| Mandriva |
MDVSA-2014:014 |
php |
2014-01-21 |
| Gentoo |
201301-01 |
firefox |
2013-01-07 |
| Debian |
DSA-2025-1 |
icedove |
2010-03-31 |
| Mandriva |
MDVSA-2010:027 |
kdelibs4 |
2010-01-27 |
| Mandriva |
MDVSA-2010:028 |
kdelibs4 |
2010-01-27 |
| Mandriva |
MDVSA-2009:203-1 |
curl |
2009-12-04 |
| Mandriva |
MDVSA-2009:315 |
libneon |
2009-12-04 |
| Mandriva |
MDVSA-2009:201-1 |
fetchmail |
2009-12-04 |
| Mandriva |
MDVSA-2009:197-3 |
nss |
2009-12-03 |
| Mandriva |
MDVSA-2009:217-3 |
mozilla-thunderbird |
2009-12-03 |
| SuSE |
SUSE-SR:2009:018 |
cyrus-imapd, neon/libneon, freeradius, strongswan, openldap2, apache2-mod_jk, expat, xpdf, mozilla-nspr |
2009-11-10 |
| Mandriva |
MDVSA-2009:203 |
curl |
2009-08-15 |
| Mandriva |
MDVSA-2009:201 |
fetchmail |
2009-08-12 |
| Red Hat |
RHSA-2009:1207-01 |
nspr nss |
2009-08-12 |
| Mandriva |
MDVSA-2009:198 |
firefox |
2009-08-07 |
| Mandriva |
MDVSA-2009:197 |
nss |
2009-08-07 |
| Ubuntu |
USN-810-2 |
nspr |
2009-08-04 |
| Ubuntu |
USN-810-1 |
nss |
2009-08-04 |
| Red Hat |
RHSA-2009:1190-01 |
nspr, nss |
2009-07-31 |
| Red Hat |
RHSA-2009:1186-01 |
nspr, nss |
2009-07-30 |
| Red Hat |
RHSA-2009:1184-01 |
nspr, nss |
2009-07-30 |
| Fedora |
FEDORA-2009-8288 |
ruby-gnome2 |
2009-08-05 |
| Fedora |
FEDORA-2009-8288 |
xulrunner |
2009-08-05 |
| Fedora |
FEDORA-2009-8288 |
yelp |
2009-08-05 |
| Fedora |
FEDORA-2009-8288 |
perl-Gtk2-MozEmbed |
2009-08-05 |
| Fedora |
FEDORA-2009-8288 |
pcmanx-gtk2 |
2009-08-05 |
| Fedora |
FEDORA-2009-8288 |
mugshot |
2009-08-05 |
| Fedora |
FEDORA-2009-8288 |
mozvoikko |
2009-08-05 |
| Fedora |
FEDORA-2009-8288 |
Miro |
2009-08-05 |
| Fedora |
FEDORA-2009-8288 |
kazehakase |
2009-08-05 |
| Fedora |
FEDORA-2009-8288 |
google-gadgets |
2009-08-05 |
| Fedora |
FEDORA-2009-8288 |
gnome-web-photo |
2009-08-05 |
| Fedora |
FEDORA-2009-8288 |
gnome-python2-extras |
2009-08-05 |
| Fedora |
FEDORA-2009-8288 |
gecko-sharp2 |
2009-08-05 |
| Fedora |
FEDORA-2009-8288 |
galeon |
2009-08-05 |
| Fedora |
FEDORA-2009-8288 |
firefox |
2009-08-05 |
| Fedora |
FEDORA-2009-8288 |
evolution-rss |
2009-08-05 |
| Fedora |
FEDORA-2009-8279 |
chmsee |
2009-08-05 |
| Fedora |
FEDORA-2009-8279 |
blam |
2009-08-05 |
| Fedora |
FEDORA-2009-8288 |
blam |
2009-08-05 |
| Slackware |
SSA:2009-215-01 |
mozilla-firefox |
2009-08-04 |
| Mandriva |
MDVSA-2009:288 |
proftpd |
2009-10-23 |
|