VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-3900
midori: Midori before 0.2.5, when WebKitGTK+ before 1.1.14 ...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3900

Original

Midori before 0.2.5, when WebKitGTK+ before 1.1.14 or LibSoup before 2.29.91 is used, does not verify X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary https web sites via a crafted server certificate, a related issue to CVE-2010-3312.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-10-14
Source Information Category:
Advisory, Alert
Last Updated:
2010-10-14




Affected Product Tags
cpe:/a:christian_dywan:midori:0.1.10
cpe:/a:christian_dywan:midori:0.2.0
cpe:/a:christian_dywan:midori:0.2.1
cpe:/a:christian_dywan:midori:0.2.2
cpe:/a:christian_dywan:midori:0.2.3
cpe:/a:christian_dywan:midori:0.2.4 and previous versions
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
X Medium [?]
Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

X None [?]
Partial [?]
Complete [?]

Alternatives




References
CONFIRM http://www.twotoasts.de/index.php?/archives/30-Validation,-vending-and-Vala.html




CONFIRM http://www.twotoasts.de/bugs/index.php?do=details&task_id=168




CONFIRM http://git.xfce.org/apps/midori/tree/ChangeLog




MISC http://www.twotoasts.de/bugs/index.php?do=details&task_id=743




MISC http://www.omgubuntu.co.uk/2010/05/midori-0-2-5-released/




MLIST [oss-security] 20100917 Re: CVE request: epiphany not checking ssl certs




Vulnerability Type Other (NVD-CWE-Other)





Copyright © 2010 JPCERT/CC All Rights Reserved.