CVE-2009-2408

Advisory lineage Upstream: 0 Downstream: 8
Modified
Published: 30 Jul 2009, 19:00
Last modified:07 Aug 2024, 05:52

Vulnerability Summary

Overall Risk (default)
medium
28/100
CVSS Score
6.8 MEDIUM
v2.0 (nvd)
EPSS Score
1.85% LOW
2% probability -0.17%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Jul 2009, 19:00
Published
Vulnerability first disclosed
07 Aug 2024, 05:52
Last Modified
Vulnerability information updated

Description

Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. NOTE: this was originally reported for Firefox before 3.5.

CVSS Metrics

  • v3.1MEDIUMScore: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 1.85% Percentile: 83%

Techniques & Countermeasures

  • CWE-295Improper Certificate Validation

    The product does not validate, or incorrectly validates, a certificate.

Affected Systems

  • canonicalubuntu_linux

    8.04 | 8.10 | 9.04

  • debiandebian_linux

    5.0

  • mozillafirefox

    < 3.0.13

  • mozillanetwork_security_services

    < 3.12.3

  • mozillaseamonkey

    < 1.1.18

  • mozillathunderbird

    < 2.0.0.23

  • opensuseopensuse

    ≥ 10.3, ≤ 11.1

  • suselinux_enterprise

    10.0 | 11.0

  • suselinux_enterprise_server

    9

References (30)