| Severity : |
Medium
|
| Published : |
2009-10-28
|
| Modified : |
2009-12-19
|
| Base Score : |
5.8
|
| Details : |
The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, which allows remote attackers to bypass intended client-hostname restrictions via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
|
| Product/Version : |
Carrier Grade CGE 5.1
Pro 4.x
CGE 4.x
Mobilinux 4.x
|
|
CVE Vulnerabilities List CVE-2009