CVE Vulnerabilities

CVE-2002-0970

Published: Sep 24, 2002 | Modified: Nov 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The SSL capability for Konqueror in KDE 3.0.2 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack.

Affected Software

Name Vendor Start Version End Version
Konqueror Kde 2.2.2 (including) 2.2.2 (including)
Konqueror Kde 3.0 (including) 3.0 (including)
Konqueror Kde 3.0.1 (including) 3.0.1 (including)
Konqueror Kde 3.0.2 (including) 3.0.2 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 RedHat *
Red Hat Linux 7.2 RedHat *
Red Hat Linux 7.3 RedHat *
Red Hat Linux 8.0 RedHat *

References