CVE-2003-0355: Medium severity Apple Safari vulnerability
Published May 30, 2003
·Updated
Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.
Affected Software
2 affected components
Apple Safari=1.0
KDE Konqueror Embedded
Event History
May 30, 2003
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Jun 9, 2003
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0355?
CVE-2003-0355 is rated as a moderate severity vulnerability due to its ability to allow remote attackers to spoof certificates.
2
How do I fix CVE-2003-0355?
To fix CVE-2003-0355, users should upgrade to Safari version 1.0 or later, which addresses the certificate validation issue.
3
What versions of Safari are affected by CVE-2003-0355?
CVE-2003-0355 affects Safari 1.0 Beta 2 (v73) and earlier versions.
4
Can CVE-2003-0355 affect other browsers?
Yes, CVE-2003-0355 also affects KDE Konqueror Embedded as it shares similar vulnerabilities in certificate validation.
5
What is the exploit risk associated with CVE-2003-0355?
The exploit risk of CVE-2003-0355 includes the potential for attackers to impersonate legitimate websites by spoofing SSL certificates.