First published: Wed May 10 2000(Updated: )
Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web server to their own malicious server, aka the "Acros-Suencksen SSL" vulnerability.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netscape Communicator | =4.05 | |
Netscape Communicator | =4.61 | |
Netscape Communicator | =4.07 | |
Netscape Communicator | =4.51 | |
Netscape Communicator | =4.06 | |
Netscape Communicator | =4.7 | |
Netscape Communicator | =4.0 | |
Netscape Communicator | =4.6 | |
Netscape Communicator | =4.5_beta | |
Netscape Communicator | =4.72 | |
Netscape Communicator | =4.5 | |
=4.0 | ||
=4.05 | ||
=4.5 | ||
=4.5_beta | ||
=4.06 | ||
=4.6 | ||
=4.07 | ||
=4.7 | ||
=4.51 | ||
=4.61 | ||
=4.72 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0406 is considered a moderate severity vulnerability because it allows attackers to potentially intercept sensitive user information.
To fix CVE-2000-0406, users should upgrade to Netscape Communicator version 4.73 or later, or Navigator version 4.08 or later.
CVE-2000-0406 is a vulnerability in Netscape Communicator and Navigator that allows unvalidated SSL certificate handling, enabling traffic redirection to malicious servers.
CVE-2000-0406 affects users of Netscape Communicator versions before 4.73 and Navigator versions before 4.08.
Attackers exploiting CVE-2000-0406 can redirect user traffic from legitimate websites to fraudulent ones, facilitating data theft.