Lucene search

K
cve[email protected]CVE-2009-3639
HistoryOct 28, 2009 - 2:30 p.m.

CVE-2009-3639

2009-10-2814:30:00
CWE-310
web.nvd.nist.gov
276
proftpd
mod_tls
tls
x.509
cve-2009-3639
nvd
security

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

6.2 Medium

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

75.8%

The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a ‘\0’ character in a domain name in the Subject Alternative Name field of an X.509 client certificate, which allows remote attackers to bypass intended client-hostname restrictions via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Affected configurations

NVD
Node
proftpdproftpdRange1.3.2a
OR
proftpdproftpdMatch1.3.1
OR
proftpdproftpdMatch1.3.2
OR
proftpdproftpdMatch1.3.2rc1
OR
proftpdproftpdMatch1.3.2rc2
OR
proftpdproftpdMatch1.3.2rc4
OR
proftpdproftpdMatch1.3.3rc1

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

6.2 Medium

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

75.8%