Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-1194

Опубликовано: 31 мар. 2010
Источник: ubuntu
Приоритет: medium
CVSS2: 6.8

Описание

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

1.0.6-1build1
hardy

ignored

end of life
intrepid

ignored

end of life, was needed
jaunty

ignored

end of life
karmic

ignored

end of life
lucid

not-affected

1.0.4-4
maverick

not-affected

1.0.4-5
natty

not-affected

1.0.6-1
upstream

released

1.0.4-2

Показывать по

6.8 Medium

CVSS2

Связанные уязвимости

redhat
почти 16 лет назад

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.

nvd
больше 15 лет назад

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.

debian
больше 15 лет назад

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and p ...

github
больше 3 лет назад

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.

6.8 Medium

CVSS2