CVE-2002-0970: High severity KDE Konqueror vulnerability
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Other sources
The SSL capability for Konqueror in KDE 3.0.2 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0970?
CVE-2002-0970 is classified as a moderate severity vulnerability due to the risk of man-in-the-middle attacks.
How do I fix CVE-2002-0970?
To fix CVE-2002-0970, upgrade to KDE Konqueror version 3.0.3 or later, which contains the necessary security patches.
What versions of KDE Konqueror are affected by CVE-2002-0970?
CVE-2002-0970 affects KDE Konqueror versions 3.0.2, 3.0.1, 3.0, and 2.2.2.
What causes the vulnerability in CVE-2002-0970?
The vulnerability in CVE-2002-0970 is caused by the SSL capability in Konqueror not verifying the Basic Constraints for intermediate CA-signed certificates.
Can CVE-2002-0970 lead to data compromise?
Yes, CVE-2002-0970 can potentially lead to data compromise by allowing attackers to intercept and manipulate SSL traffic.