Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24805
HistoryApr 10, 2020 - 1:06 a.m.

Spoofable Common Name Of A Certificate

2020-04-1001:06:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

EPSS

0.006

Percentile

77.6%

The kdelibs and kdelibs3 packages is vulnerable to spoofing of common name of a certificate. An input sanitization flaw was found in the KSSL (KDE SSL Wrapper) API. An attacker could supply a specially-crafted SSL certificate (for example, via a web page) to an application using KSSL, such as the Konqueror web browser, causing misleading information to be presented to the user, possibly tricking them into accepting the certificate as valid.