Lucene search

K
cveMitreCVE-2010-3900
HistoryOct 14, 2010 - 5:58 a.m.

CVE-2010-3900

2010-10-1405:58:42
mitre
web.nvd.nist.gov
27
midori
webkitgtk+
libsoup
x.509 certificates
man-in-the-middle attack
cve-2010-3900

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

8.3

Confidence

High

EPSS

0.003

Percentile

68.6%

Midori before 0.2.5, when WebKitGTK+ before 1.1.14 or LibSoup before 2.29.91 is used, does not verify X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary https web sites via a crafted server certificate, a related issue to CVE-2010-3312.

Affected configurations

Nvd
Node
christian_dywanmidoriRange0.2.4
OR
christian_dywanmidoriMatch0.1.10
OR
christian_dywanmidoriMatch0.2.0
OR
christian_dywanmidoriMatch0.2.1
OR
christian_dywanmidoriMatch0.2.2
OR
christian_dywanmidoriMatch0.2.3
VendorProductVersionCPE
christian_dywanmidori*cpe:2.3:a:christian_dywan:midori:*:*:*:*:*:*:*:*
christian_dywanmidori0.1.10cpe:2.3:a:christian_dywan:midori:0.1.10:*:*:*:*:*:*:*
christian_dywanmidori0.2.0cpe:2.3:a:christian_dywan:midori:0.2.0:*:*:*:*:*:*:*
christian_dywanmidori0.2.1cpe:2.3:a:christian_dywan:midori:0.2.1:*:*:*:*:*:*:*
christian_dywanmidori0.2.2cpe:2.3:a:christian_dywan:midori:0.2.2:*:*:*:*:*:*:*
christian_dywanmidori0.2.3cpe:2.3:a:christian_dywan:midori:0.2.3:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

8.3

Confidence

High

EPSS

0.003

Percentile

68.6%