CVE Database
/

CVE-2002-0970

Back to search

CVE-2002-0970

Published: Sep 1, 2004

Modified: Aug 8, 2024

PUBLISHED

Description

The SSL capability for Konqueror in KDE 3.0.2 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack.

VendorProductVersions

n/a

n/a

affected
n/a

References

ssl-ca-certificate-spoofing(9776)
vdb-entry
x_refsource_XF
RHSA-2002:220
vendor-advisory
x_refsource_REDHAT
5410
vdb-entry
x_refsource_BID
CLA-2002:519
vendor-advisory
x_refsource_CONECTIVA
RHSA-2002:221
vendor-advisory
x_refsource_REDHAT
DSA-155
vendor-advisory
x_refsource_DEBIAN
MDKSA-2002:058
vendor-advisory
x_refsource_MANDRAKE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now