CVE-2009-2408
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509…
Does this matter?
Lower severity and a low EPSS score (4.96%). Track it; it rarely justifies an emergency change on its own.
Description
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. NOTE: this was originally reported for Firefox before 3.5.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 4.96% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- mozilla/firefox · mozilla/network security services · mozilla/seamonkey · mozilla/thunderbird · opensuse/opensuse · suse/linux enterprise · suse/linux enterprise server · debian/debian linux · canonical/ubuntu linux
- Source
- secalert@redhat.com
References
- http://isc.sans.org/diary.html?storyid=7003Broken Link
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.htmlMailing List
- http://marc.info/?l=oss-security&m=125198917018936&w=2Mailing List
- http://osvdb.org/56723Broken Link
- http://secunia.com/advisories/36088Broken Link, Vendor Advisory
- http://secunia.com/advisories/36125Broken Link, Vendor Advisory
- http://secunia.com/advisories/36139Broken Link, Vendor Advisory
- http://secunia.com/advisories/36157Broken Link, Vendor Advisory
- http://secunia.com/advisories/36434Broken Link, Vendor Advisory
- http://secunia.com/advisories/36669Broken Link
- http://secunia.com/advisories/37098Broken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021030.1-1Broken Link
- http://www.debian.org/security/2009/dsa-1874Mailing List
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:197Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:216Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:217Broken Link
- http://www.mozilla.org/security/announce/2009/mfsa2009-42.htmlVendor Advisory
- http://www.novell.com/linux/security/advisories/2009_48_firefox.htmlBroken Link
- http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_m.c.diff?r1=1.8&r2=1.11&f=hBroken Link
- http://www.redhat.com/support/errata/RHSA-2009-1207.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2009-1432.htmlBroken Link
- http://www.securitytracker.com/id?1022632Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-810-1Third Party Advisory
- http://www.vupen.com/english/advisories/2009/2085Broken Link, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/3184Broken Link
- http://www.wired.com/threatlevel/2009/07/kaminsky/Press/Media Coverage
- https://bugzilla.redhat.com/show_bug.cgi?id=510251Issue Tracking
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10751Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8458Broken Link
- https://usn.ubuntu.com/810-2/Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.