CVE Vulnerabilities

CVE-2014-3504

Published: Aug 19, 2014 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in the subjects Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

Affected Software

Name Vendor Start Version End Version
Subversion Apache 1.4.0 (including) 1.4.0 (including)
Subversion Apache 1.4.1 (including) 1.4.1 (including)
Subversion Apache 1.4.2 (including) 1.4.2 (including)
Subversion Apache 1.4.3 (including) 1.4.3 (including)
Subversion Apache 1.4.4 (including) 1.4.4 (including)
Subversion Apache 1.4.5 (including) 1.4.5 (including)
Subversion Apache 1.4.6 (including) 1.4.6 (including)
Subversion Apache 1.5.0 (including) 1.5.0 (including)
Subversion Apache 1.5.1 (including) 1.5.1 (including)
Subversion Apache 1.5.2 (including) 1.5.2 (including)
Subversion Apache 1.5.3 (including) 1.5.3 (including)
Subversion Apache 1.5.4 (including) 1.5.4 (including)
Subversion Apache 1.5.5 (including) 1.5.5 (including)
Subversion Apache 1.5.6 (including) 1.5.6 (including)
Subversion Apache 1.5.7 (including) 1.5.7 (including)
Subversion Apache 1.5.8 (including) 1.5.8 (including)
Subversion Apache 1.6.0 (including) 1.6.0 (including)
Subversion Apache 1.6.1 (including) 1.6.1 (including)
Subversion Apache 1.6.2 (including) 1.6.2 (including)
Subversion Apache 1.6.3 (including) 1.6.3 (including)
Subversion Apache 1.6.4 (including) 1.6.4 (including)
Subversion Apache 1.6.5 (including) 1.6.5 (including)
Subversion Apache 1.6.6 (including) 1.6.6 (including)
Subversion Apache 1.6.7 (including) 1.6.7 (including)
Subversion Apache 1.6.8 (including) 1.6.8 (including)
Subversion Apache 1.6.9 (including) 1.6.9 (including)
Subversion Apache 1.6.10 (including) 1.6.10 (including)
Subversion Apache 1.6.11 (including) 1.6.11 (including)
Subversion Apache 1.6.12 (including) 1.6.12 (including)
Subversion Apache 1.6.13 (including) 1.6.13 (including)
Subversion Apache 1.6.14 (including) 1.6.14 (including)
Subversion Apache 1.6.15 (including) 1.6.15 (including)
Subversion Apache 1.6.16 (including) 1.6.16 (including)
Subversion Apache 1.6.17 (including) 1.6.17 (including)
Subversion Apache 1.6.18 (including) 1.6.18 (including)
Subversion Apache 1.6.19 (including) 1.6.19 (including)
Subversion Apache 1.6.20 (including) 1.6.20 (including)
Subversion Apache 1.6.21 (including) 1.6.21 (including)
Subversion Apache 1.6.23 (including) 1.6.23 (including)
Subversion Apache 1.7.0 (including) 1.7.0 (including)
Subversion Apache 1.7.1 (including) 1.7.1 (including)
Subversion Apache 1.7.2 (including) 1.7.2 (including)
Subversion Apache 1.7.3 (including) 1.7.3 (including)
Subversion Apache 1.7.4 (including) 1.7.4 (including)
Subversion Apache 1.7.5 (including) 1.7.5 (including)
Subversion Apache 1.7.6 (including) 1.7.6 (including)
Subversion Apache 1.7.7 (including) 1.7.7 (including)
Subversion Apache 1.7.8 (including) 1.7.8 (including)
Subversion Apache 1.7.9 (including) 1.7.9 (including)
Subversion Apache 1.7.10 (including) 1.7.10 (including)
Subversion Apache 1.7.11 (including) 1.7.11 (including)
Subversion Apache 1.7.12 (including) 1.7.12 (including)
Subversion Apache 1.7.13 (including) 1.7.13 (including)
Subversion Apache 1.7.14 (including) 1.7.14 (including)
Subversion Apache 1.7.15 (including) 1.7.15 (including)
Subversion Apache 1.7.16 (including) 1.7.16 (including)
Subversion Apache 1.7.17 (including) 1.7.17 (including)
Subversion Apache 1.8.0 (including) 1.8.0 (including)
Subversion Apache 1.8.1 (including) 1.8.1 (including)
Subversion Apache 1.8.2 (including) 1.8.2 (including)
Subversion Apache 1.8.3 (including) 1.8.3 (including)
Subversion Apache 1.8.4 (including) 1.8.4 (including)
Subversion Apache 1.8.5 (including) 1.8.5 (including)
Subversion Apache 1.8.6 (including) 1.8.6 (including)
Subversion Apache 1.8.7 (including) 1.8.7 (including)
Subversion Apache 1.8.8 (including) 1.8.8 (including)
Subversion Apache 1.8.9 (including) 1.8.9 (including)
Serf Ubuntu lucid *
Serf Ubuntu precise *
Serf Ubuntu trusty *
Serf Ubuntu upstream *

References