The SSL capability for Konqueror in KDE 3.0.2 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2002-09-23 21:00
Updated : 2017-10-09 18:30
NVD link : CVE-2002-0970
Mitre link : CVE-2002-0970
JSON object : View
CWE
Products Affected
kde
- konqueror
- kde