Multiple Vendor SSL Certificate Validation Vulnerability
BID:3803
Info
Multiple Vendor SSL Certificate Validation Vulnerability
| Bugtraq ID: | 3803 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 03 2002 12:00AM |
| Updated: | Jan 03 2002 12:00AM |
| Credit: | Published to the BugTraq mailing list by [email protected] on January 3, 2002. |
| Vulnerable: |
W3M W3M 0.2.3 W3M W3M 0.2.2 W3M W3M 0.2.1 W3M W3M 0.2 W3M W3M 0.1.10 W3M W3M 0.1.9 W3M W3M 0.1.8 W3M W3M 0.1.7 W3M W3M 0.1.6 W3M W3M 0.1.4 W3M W3M 0.1.3 University of Kansas Lynx 2.8.4 University of Kansas Lynx 2.8 University of Kansas Lynx 2.7 Twibright Labs Links 0.96 |
| Not Vulnerable: |
W3M W3M 0.2.4 |
Discussion
Multiple Vendor SSL Certificate Validation Vulnerability
When an SSL connection is made, the identify of the foreign site may be verified through the use of an SSL certificate. This would normally prevent the possibility of spoofing a trusted site, or of implementing a man in the middle attack. Generally this verification is done through the eventual use of a root signing authority.
Certain web browsers have implemented SSL functionality without including the ability to verify certificates. If an explicit warning is not given to the user of these products when an SSL connection is initiated, the attacks detailed above may be attempted without detection.
When an SSL connection is made, the identify of the foreign site may be verified through the use of an SSL certificate. This would normally prevent the possibility of spoofing a trusted site, or of implementing a man in the middle attack. Generally this verification is done through the eventual use of a root signing authority.
Certain web browsers have implemented SSL functionality without including the ability to verify certificates. If an explicit warning is not given to the user of these products when an SSL connection is initiated, the attacks detailed above may be attempted without detection.
Exploit / POC
Multiple Vendor SSL Certificate Validation Vulnerability
No exploit code is required to take advantage of this issue.
No exploit code is required to take advantage of this issue.
Solution / Fix
Multiple Vendor SSL Certificate Validation Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Multiple Vendor SSL Certificate Validation Vulnerability
References:
References:
- Links Homepage (Links)
- Lynx Homepage (Lynx)
- W3M Homepage (W3M)