CVE-2009-3455: High severity safari vulnerability
Apple Safari, possibly before 4.0.3, on Mac OS X does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3455?
CVE-2009-3455 has a medium severity level as it enables man-in-the-middle attacks through SSL server spoofing.
How do I fix CVE-2009-3455?
To fix CVE-2009-3455, update Apple Safari to version 4.0.3 or later.
What systems are affected by CVE-2009-3455?
CVE-2009-3455 affects multiple versions of Apple Safari prior to 4.0.3 on Mac OS X.
What does CVE-2009-3455 exploit?
CVE-2009-3455 exploits improper handling of a '\0' character in a domain name within an X.509 certificate.
Who can be affected by CVE-2009-3455?
Users of vulnerable versions of Apple Safari can be affected by CVE-2009-3455 if they connect to malicious SSL servers.