CVE Vulnerabilities

CVE-2009-2474

Inadequate Encryption Strength

Published: Aug 21, 2009 | Modified: May 22, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a 0 character in a domain name in the subjects Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

Name Vendor Start Version End Version
Neon Webdav * 0.28.6 (excluding)

Potential Mitigations

References