kio/kio/tcpslavebase.cpp in KDE KSSL in kdelibs before 4.6.1 does not properly verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a certificate issued by a legitimate Certification Authority for an IP address, a different vulnerability than CVE-2009-2702.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2011/0990 | vdb entry |
http://www.mandriva.com/security/advisories?name=MDVSA-2011:071 | vendor advisory |
http://www.securityfocus.com/bid/46789 | vdb entry |
http://secunia.com/advisories/44108 | third party advisory |
http://www.ubuntu.com/usn/USN-1110-1 | vendor advisory |
http://www.vupen.com/english/advisories/2011/0913 | vdb entry |
https://projects.kde.org/projects/kde/kdelibs/repository/revisions/76f935197599a335a5fe09b78751ddb455248cf7 | patch |
http://openwall.com/lists/oss-security/2011/03/08/13 | mailing list patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/65986 | vdb entry |
http://openwall.com/lists/oss-security/2011/03/08/20 | mailing list patch |