CVE-2000-0406: Low severity Netscape Communicator vulnerability
Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web server to their own malicious server, aka the "Acros-Suencksen SSL" vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Netscape Communicatorto a version that resolves this vulnerability.Fixed in 4.73 - Compensating control
Do not use Netscape Communicator versions before 4.73 or Navigator 4.07; restrict or block use of these affected browsers until they are replaced or a vendor-supplied fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0406?
CVE-2000-0406 is considered a moderate severity vulnerability because it allows attackers to potentially intercept sensitive user information.
How do I fix CVE-2000-0406?
To fix CVE-2000-0406, users should upgrade to Netscape Communicator version 4.73 or later, or Navigator version 4.08 or later.
What is CVE-2000-0406?
CVE-2000-0406 is a vulnerability in Netscape Communicator and Navigator that allows unvalidated SSL certificate handling, enabling traffic redirection to malicious servers.
Who is affected by CVE-2000-0406?
CVE-2000-0406 affects users of Netscape Communicator versions before 4.73 and Navigator versions before 4.08.
What can attackers do with CVE-2000-0406?
Attackers exploiting CVE-2000-0406 can redirect user traffic from legitimate websites to fraudulent ones, facilitating data theft.