First published: Mon Aug 12 2002(Updated: )
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KDE Konqueror | =3.0.2 | |
KDE Konqueror | =2.2.2 | |
KDE Konqueror | =3.0 | |
KDE Konqueror | =3.0.1 | |
KDE KDE | =3.0.2 | |
KDE KDE | =3.0.1 | |
KDE KDE | =3.0 | |
KDE KDE | =2.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0970 is classified as a moderate severity vulnerability due to the risk of man-in-the-middle attacks.
To fix CVE-2002-0970, upgrade to KDE Konqueror version 3.0.3 or later, which contains the necessary security patches.
CVE-2002-0970 affects KDE Konqueror versions 3.0.2, 3.0.1, 3.0, and 2.2.2.
The vulnerability in CVE-2002-0970 is caused by the SSL capability in Konqueror not verifying the Basic Constraints for intermediate CA-signed certificates.
Yes, CVE-2002-0970 can potentially lead to data compromise by allowing attackers to intercept and manipulate SSL traffic.