CVE Vulnerabilities

CVE-2009-3490

Published: Sep 30, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
4 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

GNU Wget before 1.12 does not properly handle a 0 character in a domain name in the Common Name field of an X.509 certificate, which allows man-in-the-middle remote attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Affected Software

NameVendorStart VersionEnd Version
WgetGnu*1.11.4 (including)
WgetGnu1.5.3 (including)1.5.3 (including)
WgetGnu1.6 (including)1.6 (including)
WgetGnu1.7 (including)1.7 (including)
WgetGnu1.7.1 (including)1.7.1 (including)
WgetGnu1.8 (including)1.8 (including)
WgetGnu1.8.1 (including)1.8.1 (including)
WgetGnu1.9 (including)1.9 (including)
WgetGnu1.9.1 (including)1.9.1 (including)
WgetGnu1.10 (including)1.10 (including)
WgetGnu1.10.1 (including)1.10.1 (including)
WgetGnu1.10.2 (including)1.10.2 (including)
WgetGnu1.11 (including)1.11 (including)
WgetGnu1.11.1 (including)1.11.1 (including)
WgetGnu1.11.2 (including)1.11.2 (including)
WgetGnu1.11.3 (including)1.11.3 (including)
Red Hat Enterprise Linux 3RedHatwget-0:1.10.2-0.30E.1*
Red Hat Enterprise Linux 4RedHatwget-0:1.10.2-1.el4_8.1*
Red Hat Enterprise Linux 5RedHatwget-0:1.11.4-2.el5_4.1*
WgetUbuntudapper*
WgetUbuntudevel*
WgetUbuntuhardy*
WgetUbuntuintrepid*
WgetUbuntujaunty*
WgetUbuntuupstream*

References