Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wqwx-p8fg-v9px

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.

EPSS

Процентиль: 57%
0.00352
Низкий

Связанные уязвимости

ubuntu
больше 15 лет назад

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.

redhat
почти 16 лет назад

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.

nvd
больше 15 лет назад

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.

debian
больше 15 лет назад

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and p ...

EPSS

Процентиль: 57%
0.00352
Низкий