Multiple Vendor SSL Certificate Validation Vulnerability

BID:3803

Info

Multiple Vendor SSL Certificate Validation Vulnerability

Bugtraq ID: 3803
Class: Design Error
CVE:
Remote: Yes
Local: No
Published: Jan 03 2002 12:00AM
Updated: Jan 03 2002 12:00AM
Credit: Published to the BugTraq mailing list by [email protected] on January 3, 2002.
Vulnerable: W3M W3M 0.2.3
W3M W3M 0.2.2
W3M W3M 0.2.1
+ Redhat Linux 7.2 ia64
+ Redhat Linux 7.2 i386
+ Redhat Linux 7.2
W3M W3M 0.2
+ Redhat Linux 7.0 i386
+ Redhat Linux 7.0
W3M W3M 0.1.10
W3M W3M 0.1.9
W3M W3M 0.1.8
W3M W3M 0.1.7
W3M W3M 0.1.6
W3M W3M 0.1.4
W3M W3M 0.1.3
University of Kansas Lynx 2.8.4
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Workstation 3.1.1
+ Caldera OpenLinux Workstation 3.1
+ Debian Linux 3.0
+ Redhat Linux for iSeries 7.1
+ Redhat Linux for pSeries 7.1
+ Sun Linux 5.0.6
+ Trustix Secure Linux 1.5
+ Trustix Secure Linux 1.2
+ Trustix Secure Linux 1.1
University of Kansas Lynx 2.8
University of Kansas Lynx 2.7
Twibright Labs Links 0.96
Not Vulnerable: W3M W3M 0.2.4

Discussion

Multiple Vendor SSL Certificate Validation Vulnerability

When an SSL connection is made, the identify of the foreign site may be verified through the use of an SSL certificate. This would normally prevent the possibility of spoofing a trusted site, or of implementing a man in the middle attack. Generally this verification is done through the eventual use of a root signing authority.

Certain web browsers have implemented SSL functionality without including the ability to verify certificates. If an explicit warning is not given to the user of these products when an SSL connection is initiated, the attacks detailed above may be attempted without detection.

Exploit / POC

Multiple Vendor SSL Certificate Validation Vulnerability

No exploit code is required to take advantage of this issue.

Solution / Fix

Multiple Vendor SSL Certificate Validation Vulnerability

Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

References

Multiple Vendor SSL Certificate Validation Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report