CVE Vulnerabilities

CVE-2009-2474

Inadequate Encryption Strength

Published: Aug 21, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
4 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a 0 character in a domain name in the subjects Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

NameVendorStart VersionEnd Version
NeonWebdav*0.28.6 (excluding)
Red Hat Enterprise Linux 4RedHatneon-0:0.24.7-4.el4_8.2*
Red Hat Enterprise Linux 5RedHatneon-0:0.25.5-10.el5_4.1*
NeonUbuntudapper*
Neon26Ubuntuhardy*
Neon26Ubuntuintrepid*
Neon26Ubuntujaunty*
Neon26Ubuntukarmic*
Neon26Ubuntulucid*
Neon27Ubuntuhardy*
Neon27Ubuntuintrepid*
Neon27Ubuntujaunty*
Neon27Ubuntuupstream*

Potential Mitigations

References