First published: Fri May 30 2003(Updated: )
Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Safari | =1.0 | |
KDE Konqueror |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0355 is rated as a moderate severity vulnerability due to its ability to allow remote attackers to spoof certificates.
To fix CVE-2003-0355, users should upgrade to Safari version 1.0 or later, which addresses the certificate validation issue.
CVE-2003-0355 affects Safari 1.0 Beta 2 (v73) and earlier versions.
Yes, CVE-2003-0355 also affects KDE Konqueror Embedded as it shares similar vulnerabilities in certificate validation.
The exploit risk of CVE-2003-0355 includes the potential for attackers to impersonate legitimate websites by spoofing SSL certificates.