CVE Vulnerabilities

CVE-2002-0862

Improper Certificate Validation

Published: Oct 04, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
Windows_2000Microsoft- (including)- (including)
Windows_98Microsoft- (including)- (including)
Windows_98seMicrosoft- (including)- (including)
Windows_meMicrosoft- (including)- (including)
Windows_ntMicrosoft4.0 (including)4.0 (including)
Windows_xpMicrosoft- (including)- (including)

Potential Mitigations

References