CVE Database
/

CVE-2009-3475

Back to search

CVE-2009-3475

Published: Sep 29, 2009

Modified: Sep 17, 2024

PUBLISHED

Description

Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before 2.2.1, when using PKIX trust validation, does not properly handle a '\0' character in the subject or subjectAltName fields of a certificate, which allows remote man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

VendorProductVersions

n/a

n/a

affected
n/a

References

36876
third-party-advisory
x_refsource_SECUNIA
DSA-1896
vendor-advisory
x_refsource_DEBIAN
DSA-1895
vendor-advisory
x_refsource_DEBIAN
36861
third-party-advisory
x_refsource_SECUNIA
36855
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now