CVE Vulnerabilities

CVE-2009-2474

Inadequate Encryption Strength

Published: Aug 21, 2009 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
4 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a 0 character in a domain name in the subjects Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Weakness 

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software 

Name Vendor Start Version End Version
Neon Webdav * 0.28.6 (excluding)
Neon Ubuntu dapper *
Neon26 Ubuntu hardy *
Neon26 Ubuntu intrepid *
Neon26 Ubuntu jaunty *
Neon26 Ubuntu karmic *
Neon26 Ubuntu lucid *
Neon27 Ubuntu hardy *
Neon27 Ubuntu intrepid *
Neon27 Ubuntu jaunty *
Neon27 Ubuntu upstream *
Red Hat Enterprise Linux 4 RedHat neon-0:0.24.7-4.el4_8.2 *
Red Hat Enterprise Linux 5 RedHat neon-0:0.25.5-10.el5_4.1 *

Potential Mitigations 

References