Lucene search

K
cvelistCanonicalCVELIST:CVE-2010-1194
HistoryMar 31, 2010 - 5:35 p.m.

CVE-2010-1194

2010-03-3117:35:00
canonical
www.cve.org
1

5.5 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

75.1%

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.

5.5 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

75.1%