CVE-2009-2702

Publication date 8 September 2009

Last updated 24 July 2024


Ubuntu priority

KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Read the notes from the security team

Status

Package Ubuntu Release Status
kde4libs 10.04 LTS lucid
Fixed 4:4.3.1-0ubuntu3
9.10 karmic
Fixed 4:4.3.1-0ubuntu3
9.04 jaunty
Fixed 4:4.2.2-0ubuntu5.2
8.10 intrepid
Fixed 4:4.1.4-0ubuntu1~intrepid1.3
8.04 LTS hardy Ignored end of life
6.06 LTS dapper Not in release
kdelibs 10.04 LTS lucid
Fixed 4:3.5.10.dfsg.1-2ubuntu5
9.10 karmic
Fixed 4:3.5.10.dfsg.1-2ubuntu5
9.04 jaunty
Fixed 4:3.5.10.dfsg.1-1ubuntu8.2
8.10 intrepid
Fixed 4:3.5.10-0ubuntu6.2
8.04 LTS hardy
Fixed 4:3.5.10-0ubuntu1~hardy1.3
6.06 LTS dapper Ignored end of life

Notes


jdstrand

kde4libs not as serious since KDE4 has moved to Qt4. However, it should be fixed due to other applications may use it. Also, by nad checin verification (ie non-netowork) will use kssl.

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
kdelibs

References

Related Ubuntu Security Notices (USN)

    • USN-833-1
    • KDE-Libs vulnerability
    • 17 September 2009

Other references