Netscape 4.73 and earlier does not properly warn users about a potentially invalid certificate if the user has previously accepted the certificate for a different web site, which could allow remote attackers to spoof a legitimate web site by compromising that sites DNS information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Communicator | Netscape | 4.0 (including) | 4.0 (including) |
Communicator | Netscape | 4.5 (including) | 4.5 (including) |
Communicator | Netscape | 4.6 (including) | 4.6 (including) |
Communicator | Netscape | 4.7 (including) | 4.7 (including) |
Communicator | Netscape | 4.51 (including) | 4.51 (including) |
Communicator | Netscape | 4.61 (including) | 4.61 (including) |
Communicator | Netscape | 4.72 (including) | 4.72 (including) |
Communicator | Netscape | 4.73 (including) | 4.73 (including) |