CVE-2009-3765
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
mutt_ssl.c in mutt 1.5.19 and 1.5.20, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
mutt_ssl.c en mutt 1.5.19 y 1.5.20, cuando usa OenSSL, no maneja de forma adecuada el caracter '\0' en un nombre de dominio, dentro del campo sujeto del Common Name (CN) en los certificados X.509, lo que permite a atacantes man-in-the-middle, espíar servidores SSL de su elección a través de certificados manipulados concedidos por Autoridades Certificadoras, esta relacionado con CVE-2009-2408.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-10-23 CVE Reserved
- 2009-10-23 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-310: Cryptographic Issues
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://dev.mutt.org/trac/changeset/6016:dc09812e63a3/mutt_ssl.c | X_refsource_confirm | |
http://marc.info/?l=oss-security&m=125198917018936&w=2 | Mailing List | |
http://marc.info/?l=oss-security&m=125369675820512&w=2 | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html | 2009-10-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.19 Search vendor "Mutt" for product "Mutt" and version "1.5.19" | - |
Affected
| in | Openssl Search vendor "Openssl" | Openssl Search vendor "Openssl" for product "Openssl" | * | - |
Safe
|
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.20 Search vendor "Mutt" for product "Mutt" and version "1.5.20" | - |
Affected
| in | Openssl Search vendor "Openssl" | Openssl Search vendor "Openssl" for product "Openssl" | * | - |
Safe
|