First published: Thu Jun 05 2003(Updated: )
Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | =1.0-beta | |
Apple Mobile Safari | =1.0-beta2 | |
KDE Konqueror Embedded | =0.1 | |
Red Hat Linux | =7.2 | |
Turbolinux Server | =7.0 | |
Turbolinux Workstation | =7.0 | |
Turbolinux Workstation | =8.0 | |
KDE KDE | <=2.2.2 | |
Turbolinux Server | =8.0 | |
Red Hat Linux | =7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0370 is considered a medium severity vulnerability due to its potential for man-in-the-middle attacks.
To fix CVE-2003-0370, update to a version of KDE or Konqueror that properly validates the Common Name (CN) field of X.509 certificates.
CVE-2003-0370 impacts KDE versions up to 2.2.2 and Konqueror Embedded version 0.1, as well as specific versions of Apple Safari and Red Hat Linux.
Yes, CVE-2003-0370 allows attackers to spoof certificates due to improper validation of the CN field.
Yes, CVE-2003-0370 can be exploited remotely through a man-in-the-middle attack.