Firefox / Konqueror / Safari certificate spoofing
news
/
advisories
/
forum
/
software
/
advertising
/
search
/
exploits
[EN]
securityvulns.ru
no-pyccku
Firefox / Konqueror / Safari certificate spoofing
updated since 19.11.2007
Published:
20.11.2007
Source:
FULL-DISCLOSURE
SecurityVulns ID:
8359
Type:
remote
Level:
5
/10
Description:
Link between certificate and web site is not set, if certificate from unknown certification authirity is manually approved, making it's possible to use same certificate for different site withour warning.
Affected:
APPLE
:
Safari 2.0
MOZILLA
:
Firefox 2.0
KDE
:
Konqueror 3.5
APPLE
:
Safari 3.0
KDE
:
Konqueror 3.95
Original document
Graeme Fowler
,
Re: Certificate spoofing issue with Mozilla, Konqueror, Safari 2
(
20.11.2007
)
Nils Toedtmann
,
ertificate spoofing with subjectAltName and domain name wildcards
(
19.11.2007
)
Nils Toedtmann
,
[Full-disclosure] Certificate spoofing issue with Mozilla, Konqueror, Safari 2
(
19.11.2007
)
Discuss:
Read or add your comments to this news (0 comments)
About
|
Terms of use
|
Privacy Policy
©
SecurityVulns
,
3APA3A
, Vladimir Dubrovin
Enter your search terms
Web
securityvulns.com
Submit search form