CVE-2007-6591: Medium severity Konqueror vulnerability
KDE Konqueror 3.5.5 and 3.95.00, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regards the certificate as also accepted for all domain names in subjectAltName:dNSName fields, even though these fields cannot be examined in the product, which makes it easier for remote attackers to trick a user into accepting an invalid certificate for a spoofed web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6591?
CVE-2007-6591 is classified as a moderate severity vulnerability.
How do I fix CVE-2007-6591?
To mitigate CVE-2007-6591, upgrade to a newer version of KDE Konqueror that addresses this issue.
What versions are affected by CVE-2007-6591?
CVE-2007-6591 affects KDE Konqueror versions 3.5.5 and 3.95.00.
What is the impact of CVE-2007-6591?
The impact of CVE-2007-6591 allows attackers to exploit accepted SSL certificates for unauthorized domain names.
Can CVE-2007-6591 lead to man-in-the-middle attacks?
Yes, CVE-2007-6591 can potentially lead to man-in-the-middle attacks due to improper handling of SSL certificates.