CVE-2000-0517: Medium severity Netscape Communicator vulnerability
Netscape 4.73 and earlier does not properly warn users about a potentially invalid certificate if the user has previously accepted the certificate for a different web site, which could allow remote attackers to spoof a legitimate web site by compromising that site's DNS information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Clear any previously accepted/locally stored SSL/TLS certificate exceptions and disable storing permanent certificate exceptions so the browser will warn on certificate-hostname mismatches.
Netscape Communicator accepted_certificate_exceptions = remove and disable - Compensating control
Mitigate risk from DNS compromise by restricting administrative access to DNS management, monitoring and alerting on DNS record changes, and applying DNS integrity protections where available.
- Operational
Instruct users to never accept a certificate warning for a site unless the certificate and hostname are verified through an independent trusted channel. Audit and remove any accepted certificates that were granted for a different hostname.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0517?
CVE-2000-0517 is considered a moderate severity vulnerability due to its potential for allowing attackers to spoof legitimate websites.
How do I fix CVE-2000-0517?
To fix CVE-2000-0517, users should upgrade to a more secure version of Netscape that addresses this vulnerability.
What versions of Netscape are affected by CVE-2000-0517?
CVE-2000-0517 affects Netscape versions 4.0 through 4.73, including all iterations of version 4.x.
What issue does CVE-2000-0517 cause?
CVE-2000-0517 can lead to users not being properly warned about invalid certificates, making them vulnerable to phishing attacks.
Can CVE-2000-0517 be exploited remotely?
Yes, CVE-2000-0517 can be exploited remotely by attacking the DNS entries of a legitimate website.