CVE-2009-3765 Information

Share on:

Description

mutt_ssl.c in mutt 1.5.19 and 1.5.20 when OpenSSL is used does not properly handle a ‘\0’ character in a domain name in the subject’s Common Name (CN) field of an X.509 certificate which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority a related issue to CVE-2009-2408.

Reference

http://dev.mutt.org/trac/changeset/6016:dc09812e63a3/mutt_ssl.c http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html http://marc.info/?l=oss-security&m=125198917018936&w=2 http://marc.info/?l=oss-security&m=125369675820512&w=2