Apple Safari Common Name Certificate Validation Vulnerability
BID:7518
Info
Apple Safari Common Name Certificate Validation Vulnerability
| Bugtraq ID: | 7518 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 07 2003 12:00AM |
| Updated: | Jan 05 2009 09:32PM |
| Credit: | Discovery of this issue is credited to Simson L. Garfinkel and Jesse Burns. |
| Vulnerable: |
Apple Safari Beta 2 |
| Not Vulnerable: | |
Discussion
Apple Safari Common Name Certificate Validation Vulnerability
Apple Safari web browser fails to correctly validate theCommon Name (CN) field for X.509 certificates when a SSL/TLS session is negotiated. Safari is not able to detect cases where the CN does not match the hostname of the server. This could lead to a variety of attacks, including the possibility of allowing a malicious server to masquerade as a trusted server.
It has also been reported that Safari does not have a feature which allows users to inspect a certificate manually.
Apple Safari web browser fails to correctly validate theCommon Name (CN) field for X.509 certificates when a SSL/TLS session is negotiated. Safari is not able to detect cases where the CN does not match the hostname of the server. This could lead to a variety of attacks, including the possibility of allowing a malicious server to masquerade as a trusted server.
It has also been reported that Safari does not have a feature which allows users to inspect a certificate manually.
Solution / Fix
Apple Safari Common Name Certificate Validation Vulnerability
Solution:
Vendor updates are available. Please see the references for details.
Apple Safari Beta 2
Solution:
Vendor updates are available. Please see the references for details.
Apple Safari Beta 2
-
Apple Safari Public Beta 2 (v74)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=02231&plat form=osx&method=sa/index.html