|
|
Log in / Subscribe / Register

libneon: man in the middle attack

Package(s):libneon0.27 CVE #(s):CVE-2009-2474
Created:August 25, 2009 Updated:December 4, 2009
Description: From the Mandriva advisory: neon before 0.28.6, when OpenSSL is used, does not properly handle a '\0' (NUL) character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408
Alerts:
Mandriva MDVSA-2009:315 libneon 2009-12-04
Ubuntu USN-835-1 neon, neon27 2009-09-21
CentOS CESA-2009:1452 neon 2009-09-22
Red Hat RHSA-2009:1452-01 neon 2009-09-21
Mandriva MDVSA-2009:228 libneon 2009-09-10
Mandriva MDVSA-2009:221 libneon0.27 2009-08-24
CentOS CESA-2009:1452 neon 2009-10-30

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds