msmtp NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
BID:54201
Info
msmtp NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 54201 |
| Class: | Design Error |
| CVE: |
CVE-2009-3942 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 13 2009 12:00AM |
| Updated: | Dec 13 2009 12:00AM |
| Credit: | Dan Kaminsky and Moxie Marlinspike |
| Vulnerable: |
msmtp msmtp 1.4.18 Gentoo Linux |
| Not Vulnerable: |
msmtp msmtp 1.4.19 |
Discussion
msmtp NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
msmtp is prone to a security-bypass vulnerability because it fails to properly validate the domain name in a signed CA certificate, allowing attackers to substitute malicious SSL certificates for trusted ones.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers; this will aid in further attacks.
msmtp is prone to a security-bypass vulnerability because it fails to properly validate the domain name in a signed CA certificate, allowing attackers to substitute malicious SSL certificates for trusted ones.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers; this will aid in further attacks.
Exploit / POC
msmtp NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
Attackers use man-in-the-middle attacks to exploit this issue.
Attackers use man-in-the-middle attacks to exploit this issue.
Solution / Fix
msmtp NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
msmtp NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
References:
References:
- More Tricks For Defeating SSL (Moxie Marlinspike)
- msmtp Homepage (msmtp)
- Null Prefix Attacks Against SSL/TLS Certificates (Moxie Marlinspike)
- SSL flaw revealed at Black Hat (Wendy Grossman)
- Vulnerabilities Allow Attacker to Impersonate Any Website (Kim Zetter)
- (CVE-2009-3942) CVE-2009-3942 msmtp SSL NULL prefix flaw (Red Hat)