Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-3477

Опубликовано: 29 сент. 2009
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

The Blackberry Browser in RIM BlackBerry Device Software 4.5.0 before 4.5.0.173, 4.6.0 before 4.6.0.303, 4.6.1 before 4.6.1.309, 4.7.0 before 4.7.0.179, and 4.7.1 before 4.7.1.57 does not properly handle "hidden" characters including a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows remote man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:rim:blackberry_device_software:4.5.0:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_device_software:4.6:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_device_software:4.6.1:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_device_software:4.7:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_device_software:4.7.1:*:*:*:*:*:*:*

EPSS

Процентиль: 48%
0.00249
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-310

Связанные уязвимости

github
почти 4 года назад

The Blackberry Browser in RIM BlackBerry Device Software 4.5.0 before 4.5.0.173, 4.6.0 before 4.6.0.303, 4.6.1 before 4.6.1.309, 4.7.0 before 4.7.0.179, and 4.7.1 before 4.7.1.57 does not properly handle "hidden" characters including a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows remote man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

EPSS

Процентиль: 48%
0.00249
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-310