CVE-2000-0517: Medium severity Netscape Communicator vulnerability

Published May 26, 2000
·
Updated

Netscape 4.73 and earlier does not properly warn users about a potentially invalid certificate if the user has previously accepted the certificate for a different web site, which could allow remote attackers to spoof a legitimate web site by compromising that site's DNS information.

Affected Software

8 affected components
Netscape Communicator=4.61
Netscape Communicator=4.73
Netscape Communicator=4.51
Netscape Communicator=4.7
Netscape Communicator=4.0
Netscape Communicator=4.6
Netscape Communicator=4.72
Netscape Communicator=4.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Clear any previously accepted/locally stored SSL/TLS certificate exceptions and disable storing permanent certificate exceptions so the browser will warn on certificate-hostname mismatches.

    Netscape Communicator accepted_certificate_exceptions = remove and disable
  2. Compensating control

    Mitigate risk from DNS compromise by restricting administrative access to DNS management, monitoring and alerting on DNS record changes, and applying DNS integrity protections where available.

  3. Operational

    Instruct users to never accept a certificate warning for a site unless the certificate and hostname are verified through an independent trusted channel. Audit and remove any accepted certificates that were granted for a different hostname.

Event History

May 26, 2000
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Oct 13, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2000-0517?

CVE-2000-0517 is considered a moderate severity vulnerability due to its potential for allowing attackers to spoof legitimate websites.

2

How do I fix CVE-2000-0517?

To fix CVE-2000-0517, users should upgrade to a more secure version of Netscape that addresses this vulnerability.

3

What versions of Netscape are affected by CVE-2000-0517?

CVE-2000-0517 affects Netscape versions 4.0 through 4.73, including all iterations of version 4.x.

4

What issue does CVE-2000-0517 cause?

CVE-2000-0517 can lead to users not being properly warned about invalid certificates, making them vulnerable to phishing attacks.

5

Can CVE-2000-0517 be exploited remotely?

Yes, CVE-2000-0517 can be exploited remotely by attacking the DNS entries of a legitimate website.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203