CVE Vulnerabilities

CVE-2009-3490

Published: Sep 30, 2009 | Modified: Sep 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

GNU Wget before 1.12 does not properly handle a 0 character in a domain name in the Common Name field of an X.509 certificate, which allows man-in-the-middle remote attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Affected Software

Name Vendor Start Version End Version
Wget Gnu * 1.11.4 (including)
Wget Gnu 1.5.3 (including) 1.5.3 (including)
Wget Gnu 1.6 (including) 1.6 (including)
Wget Gnu 1.7 (including) 1.7 (including)
Wget Gnu 1.7.1 (including) 1.7.1 (including)
Wget Gnu 1.8 (including) 1.8 (including)
Wget Gnu 1.8.1 (including) 1.8.1 (including)
Wget Gnu 1.9 (including) 1.9 (including)
Wget Gnu 1.9.1 (including) 1.9.1 (including)
Wget Gnu 1.10 (including) 1.10 (including)
Wget Gnu 1.10.1 (including) 1.10.1 (including)
Wget Gnu 1.10.2 (including) 1.10.2 (including)
Wget Gnu 1.11 (including) 1.11 (including)
Wget Gnu 1.11.1 (including) 1.11.1 (including)
Wget Gnu 1.11.2 (including) 1.11.2 (including)
Wget Gnu 1.11.3 (including) 1.11.3 (including)

References