CVE Vulnerabilities

CVE-2009-3490

Published: Sep 30, 2009 | Modified: Sep 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
4 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

GNU Wget before 1.12 does not properly handle a 0 character in a domain name in the Common Name field of an X.509 certificate, which allows man-in-the-middle remote attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Affected Software

Name Vendor Start Version End Version
Wget Gnu * 1.11.4 (including)
Wget Gnu 1.5.3 (including) 1.5.3 (including)
Wget Gnu 1.6 (including) 1.6 (including)
Wget Gnu 1.7 (including) 1.7 (including)
Wget Gnu 1.7.1 (including) 1.7.1 (including)
Wget Gnu 1.8 (including) 1.8 (including)
Wget Gnu 1.8.1 (including) 1.8.1 (including)
Wget Gnu 1.9 (including) 1.9 (including)
Wget Gnu 1.9.1 (including) 1.9.1 (including)
Wget Gnu 1.10 (including) 1.10 (including)
Wget Gnu 1.10.1 (including) 1.10.1 (including)
Wget Gnu 1.10.2 (including) 1.10.2 (including)
Wget Gnu 1.11 (including) 1.11 (including)
Wget Gnu 1.11.1 (including) 1.11.1 (including)
Wget Gnu 1.11.2 (including) 1.11.2 (including)
Wget Gnu 1.11.3 (including) 1.11.3 (including)
Red Hat Enterprise Linux 3 RedHat wget-0:1.10.2-0.30E.1 *
Red Hat Enterprise Linux 4 RedHat wget-0:1.10.2-1.el4_8.1 *
Red Hat Enterprise Linux 5 RedHat wget-0:1.11.4-2.el5_4.1 *
Wget Ubuntu dapper *
Wget Ubuntu devel *
Wget Ubuntu hardy *
Wget Ubuntu intrepid *
Wget Ubuntu jaunty *
Wget Ubuntu upstream *

References