Description
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. NOTE: this was originally reported for Firefox before 3.5.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Affected products
- Canonical / Ubuntu Linux9.04 – 9.04
- Canonical / Ubuntu Linux8.10 – 8.10
- Canonical / Ubuntu Linux8.04 – 8.04
- Debian / debian_linux5.0 – 5.0
- Mozilla / Firefox3.0.13
- Mozilla / Network Security Services3.12.3
- Mozilla / seamonkey1.1.18
- Mozilla / Thunderbird2.0.0.23
- openSUSE / opensuse10.3 – 11.1
- SUSE / linux_enterprise10.0 – 10.0
- SUSE / linux_enterprise11.0 – 11.0
- SUSE / linux_enterprise_server9 – 9
References
- VENDOR_ADVISORYhttp://secunia.com/advisories/36139
- VENDOR_ADVISORYhttp://secunia.com/advisories/36157
- MISChttp://www.securitytracker.com/id?1022632
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:197
- VENDOR_ADVISORYhttp://www.novell.com/linux/security/advisories/2009_48_firefox.html
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:216
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/36434
- VENDOR_ADVISORYhttp://secunia.com/advisories/36088
- MISChttp://isc.sans.org/diary.html?storyid=7003
- MISChttp://www.redhat.com/support/errata/RHSA-2009-1207.html
- MISChttp://www.wired.com/threatlevel/2009/07/kaminsky/
- VENDOR_ADVISORYhttp://secunia.com/advisories/36669
- MISChttp://osvdb.org/56723
- MISChttp://www.redhat.com/support/errata/RHSA-2009-1432.html
- VENDOR_ADVISORYhttp://www.ubuntu.com/usn/usn-810-1
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10751
- VENDOR_ADVISORYhttps://usn.ubuntu.com/810-2/
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8458
- MISChttp://sunsolve.sun.com/search/document.do?assetkey=1-77-1021030.1-1
- MISChttp://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_m.c.diff?r1=1.8&r2=1.11&f=h
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2009/3184
- VENDOR_ADVISORYhttp://secunia.com/advisories/36125
- VENDOR_ADVISORYhttp://secunia.com/advisories/37098
- MISChttp://www.mozilla.org/security/announce/2009/mfsa2009-42.html
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=510251
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2009/2085
- VENDOR_ADVISORYhttp://www.debian.org/security/2009/dsa-1874
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:217
- MAILING_LISThttp://marc.info/?l=oss-security&m=125198917018936&w=2