CVE-2009-3475

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
29/09/2009
Last modified:
09/04/2025

Description

Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before 2.2.1, when using PKIX trust validation, does not properly handle a '\0' character in the subject or subjectAltName fields of a certificate, which allows remote man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:internet2:shibboleth-sp:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:internet2:shibboleth-sp:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:internet2:shibboleth-sp:1.3f:*:*:*:*:*:*:*
cpe:2.3:a:internet2:shibboleth-sp:2.0:*:*:*:*:*:*:*
cpe:2.3:a:internet2:shibboleth-sp:2.1:*:*:*:*:*:*:*
cpe:2.3:a:internet2:shibboleth-sp:2.2:*:*:*:*:*:*:*