CVE Vulnerabilities

CVE-2010-1194

Published: Mar 31, 2010 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.

Affected Software

Name Vendor Start Version End Version
Libesmtp Stafford.uklinux 0.1 (including) 0.1 (including)
Libesmtp Stafford.uklinux 0.1-a (including) 0.1-a (including)
Libesmtp Stafford.uklinux 0.2 (including) 0.2 (including)
Libesmtp Stafford.uklinux 0.3 (including) 0.3 (including)
Libesmtp Stafford.uklinux 0.4 (including) 0.4 (including)
Libesmtp Stafford.uklinux 0.5 (including) 0.5 (including)
Libesmtp Stafford.uklinux 0.6 (including) 0.6 (including)
Libesmtp Stafford.uklinux 0.6-a (including) 0.6-a (including)
Libesmtp Stafford.uklinux 0.6.1 (including) 0.6.1 (including)
Libesmtp Stafford.uklinux 0.7.0 (including) 0.7.0 (including)
Libesmtp Stafford.uklinux 0.7.1 (including) 0.7.1 (including)
Libesmtp Stafford.uklinux 0.8.0 (including) 0.8.0 (including)
Libesmtp Stafford.uklinux 0.8.1 (including) 0.8.1 (including)
Libesmtp Stafford.uklinux 0.8.2 (including) 0.8.2 (including)
Libesmtp Stafford.uklinux 0.8.3 (including) 0.8.3 (including)
Libesmtp Stafford.uklinux 0.8.4 (including) 0.8.4 (including)
Libesmtp Stafford.uklinux 0.8.5 (including) 0.8.5 (including)
Libesmtp Stafford.uklinux 0.8.6 (including) 0.8.6 (including)
Libesmtp Stafford.uklinux 0.8.7 (including) 0.8.7 (including)
Libesmtp Stafford.uklinux 0.8.8 (including) 0.8.8 (including)
Libesmtp Stafford.uklinux 0.8.9 (including) 0.8.9 (including)
Libesmtp Stafford.uklinux 0.8.10 (including) 0.8.10 (including)
Libesmtp Stafford.uklinux 0.8.10-p1 (including) 0.8.10-p1 (including)
Libesmtp Stafford.uklinux 0.8.11 (including) 0.8.11 (including)
Libesmtp Stafford.uklinux 0.8.12 (including) 0.8.12 (including)
Libesmtp Stafford.uklinux 1.0 (including) 1.0 (including)
Libesmtp Stafford.uklinux 1.0-rc1 (including) 1.0-rc1 (including)
Libesmtp Stafford.uklinux 1.0.1 (including) 1.0.1 (including)
Libesmtp Stafford.uklinux 1.0.2 (including) 1.0.2 (including)
Libesmtp Stafford.uklinux 1.0.3 (including) 1.0.3 (including)
Libesmtp Stafford.uklinux 1.0.3-r1 (including) 1.0.3-r1 (including)
Libesmtp Stafford.uklinux 1.0.4 (including) 1.0.4 (including)
Libesmtp Ubuntu dapper *
Libesmtp Ubuntu hardy *
Libesmtp Ubuntu intrepid *
Libesmtp Ubuntu jaunty *
Libesmtp Ubuntu karmic *
Libesmtp Ubuntu upstream *

References