CVE-2007-6591
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
KDE Konqueror 3.5.5 and 3.95.00, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regards the certificate as also accepted for all domain names in subjectAltName:dNSName fields, even though these fields cannot be examined in the product, which makes it easier for remote attackers to trick a user into accepting an invalid certificate for a spoofed web site.
KDE Konqueror 3.5.5 y 3.95.00, cuando un usuario acepta un certificado de servidor SSL basándose en el nombre de dominio CN del campo DN, considera el certificado como aceptado también para todos los nombres de dominios en los campos subjectAltName:dNSName, incluso aunque estos campos no pueden ser examinados en el producto, lo cual facilita a los atacantes remotos engañar al usuario para que acepte un certificado inválido para un sitio web falso.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-12-28 CVE Reserved
- 2007-12-28 CVE Published
- 2024-08-07 CVE Updated
- 2024-10-31 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://nils.toedtmann.net/pub/subjectAltName.txt | X_refsource_misc | |
http://securityreason.com/securityalert/3498 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/483929/100/100/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/483937/100/100/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/483960/100/100/threaded | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kde Search vendor "Kde" | Konqueror Search vendor "Kde" for product "Konqueror" | 3.5.5 Search vendor "Kde" for product "Konqueror" and version "3.5.5" | - |
Affected
| ||||||
Kde Search vendor "Kde" | Konqueror Search vendor "Kde" for product "Konqueror" | 3.95.00 Search vendor "Kde" for product "Konqueror" and version "3.95.00" | - |
Affected
|