CVE Vulnerabilities

CVE-2014-3504

Published: Aug 19, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in the subjects Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

Affected Software

NameVendorStart VersionEnd Version
SubversionApache1.4.0 (including)1.4.0 (including)
SubversionApache1.4.1 (including)1.4.1 (including)
SubversionApache1.4.2 (including)1.4.2 (including)
SubversionApache1.4.3 (including)1.4.3 (including)
SubversionApache1.4.4 (including)1.4.4 (including)
SubversionApache1.4.5 (including)1.4.5 (including)
SubversionApache1.4.6 (including)1.4.6 (including)
SubversionApache1.5.0 (including)1.5.0 (including)
SubversionApache1.5.1 (including)1.5.1 (including)
SubversionApache1.5.2 (including)1.5.2 (including)
SubversionApache1.5.3 (including)1.5.3 (including)
SubversionApache1.5.4 (including)1.5.4 (including)
SubversionApache1.5.5 (including)1.5.5 (including)
SubversionApache1.5.6 (including)1.5.6 (including)
SubversionApache1.5.7 (including)1.5.7 (including)
SubversionApache1.5.8 (including)1.5.8 (including)
SubversionApache1.6.0 (including)1.6.0 (including)
SubversionApache1.6.1 (including)1.6.1 (including)
SubversionApache1.6.2 (including)1.6.2 (including)
SubversionApache1.6.3 (including)1.6.3 (including)
SubversionApache1.6.4 (including)1.6.4 (including)
SubversionApache1.6.5 (including)1.6.5 (including)
SubversionApache1.6.6 (including)1.6.6 (including)
SubversionApache1.6.7 (including)1.6.7 (including)
SubversionApache1.6.8 (including)1.6.8 (including)
SubversionApache1.6.9 (including)1.6.9 (including)
SubversionApache1.6.10 (including)1.6.10 (including)
SubversionApache1.6.11 (including)1.6.11 (including)
SubversionApache1.6.12 (including)1.6.12 (including)
SubversionApache1.6.13 (including)1.6.13 (including)
SubversionApache1.6.14 (including)1.6.14 (including)
SubversionApache1.6.15 (including)1.6.15 (including)
SubversionApache1.6.16 (including)1.6.16 (including)
SubversionApache1.6.17 (including)1.6.17 (including)
SubversionApache1.6.18 (including)1.6.18 (including)
SubversionApache1.6.19 (including)1.6.19 (including)
SubversionApache1.6.20 (including)1.6.20 (including)
SubversionApache1.6.21 (including)1.6.21 (including)
SubversionApache1.6.23 (including)1.6.23 (including)
SubversionApache1.7.0 (including)1.7.0 (including)
SubversionApache1.7.1 (including)1.7.1 (including)
SubversionApache1.7.2 (including)1.7.2 (including)
SubversionApache1.7.3 (including)1.7.3 (including)
SubversionApache1.7.4 (including)1.7.4 (including)
SubversionApache1.7.5 (including)1.7.5 (including)
SubversionApache1.7.6 (including)1.7.6 (including)
SubversionApache1.7.7 (including)1.7.7 (including)
SubversionApache1.7.8 (including)1.7.8 (including)
SubversionApache1.7.9 (including)1.7.9 (including)
SubversionApache1.7.10 (including)1.7.10 (including)
SubversionApache1.7.11 (including)1.7.11 (including)
SubversionApache1.7.12 (including)1.7.12 (including)
SubversionApache1.7.13 (including)1.7.13 (including)
SubversionApache1.7.14 (including)1.7.14 (including)
SubversionApache1.7.15 (including)1.7.15 (including)
SubversionApache1.7.16 (including)1.7.16 (including)
SubversionApache1.7.17 (including)1.7.17 (including)
SubversionApache1.8.0 (including)1.8.0 (including)
SubversionApache1.8.1 (including)1.8.1 (including)
SubversionApache1.8.2 (including)1.8.2 (including)
SubversionApache1.8.3 (including)1.8.3 (including)
SubversionApache1.8.4 (including)1.8.4 (including)
SubversionApache1.8.5 (including)1.8.5 (including)
SubversionApache1.8.6 (including)1.8.6 (including)
SubversionApache1.8.7 (including)1.8.7 (including)
SubversionApache1.8.8 (including)1.8.8 (including)
SubversionApache1.8.9 (including)1.8.9 (including)
SerfUbuntulucid*
SerfUbuntuprecise*
SerfUbuntutrusty*
SerfUbuntuupstream*

References