Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-1194

Опубликовано: 31 мар. 2010
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:stafford.uklinux:libesmtp:0.1:-:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.1:a:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.2:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.3:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.4:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.5:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.6:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.6:a:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.6.1:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.7.0:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.7.1:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.8.0:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.8.1:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.8.2:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.8.3:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.8.4:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.8.5:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.8.6:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.8.7:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.8.8:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.8.9:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.8.10:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.8.10:p1:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.8.11:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:0.8.12:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:1.0:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:1.0:rc1:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:1.0.3:r1:*:*:*:*:*:*
cpe:2.3:a:stafford.uklinux:libesmtp:1.0.4:*:*:*:*:*:*:*

EPSS

Процентиль: 57%
0.00352
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-310

Связанные уязвимости

ubuntu
больше 15 лет назад

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.

redhat
почти 16 лет назад

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.

debian
больше 15 лет назад

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and p ...

github
больше 3 лет назад

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.

EPSS

Процентиль: 57%
0.00352
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-310