CVE-2010-1194
Published Mar 31, 2010
Last updated 14 years ago
Overview
- Description
- The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.
- Source
- security@ubuntu.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-310
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.1:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A016D2D3-EE76-4DE2-A276-173395F6A063" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.1:a:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB54FDC2-8A09-41BA-B949-238CA1C2434F" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0113758D-DB03-4931-BB33-275D6A3125C6" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EDC85F8E-4752-4267-9945-E514424A15E7" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34F9DE95-01E6-4939-A5D5-723A6C26E8C2" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2D8EBBED-D518-4FE6-9722-FE96156ADCBF" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8F747504-1B8B-4838-B95B-AD8FCA966A2A" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.6:a:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F871ED10-3FCA-4E32-8515-AE2211C958D9" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3541B6CC-AFA2-4F62-A857-37577573EEB5" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9021CCAF-5800-4496-A5CE-234A032A2E10" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "246D55A7-E0C7-4B0D-B949-DCFF68C0634A" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.8.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9BD3F317-F430-41E6-9082-FE3DFB12EFB1" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.8.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5218A899-88B9-484A-B6A8-A25960BAA9F1" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.8.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8EF0F5D8-6991-4FE0-A0A6-D5B52DF3A811" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.8.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4AFB4394-0F64-438E-B75D-F3F52CBF08E5" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.8.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1EE39BF3-425D-4F79-B1E9-01A489C00DE5" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.8.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5A2CCA42-428A-4F9A-B5CB-CB49D593835B" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.8.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D0B443A8-E04F-41C1-A186-2A153BE1C269" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.8.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7C93C845-A736-4FD3-BF88-3B36E2AC2EE3" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.8.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "101A6FAC-8566-4E11-93E9-568DC018894F" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.8.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "134AA471-AEB0-403B-8B60-274E09047263" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.8.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C20A0E7C-3036-46F0-9C56-6A5685ED228F" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.8.10:p1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1E1DC40D-B9B5-4BA6-93FA-08AC7019FC62" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.8.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2D0D5BCE-DAA9-4336-8928-6D5C6842190D" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:0.8.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0FFF7DED-5D47-4FB2-B0CF-ED63BE816259" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E80CB462-C4DB-46F8-B925-AF2A6AABEABE" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:1.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2EAF1E2E-9435-465E-B159-22B7CA616730" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5DB9A308-18D7-4737-9EEF-7827F8A20CB9" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5C9A1AA9-23FD-49F1-8938-3AA9D3142017" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:1.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "51E63477-32B1-498C-8EA8-ADAACBAEB0C3" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:1.0.3:r1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "50F6AC34-17C2-4E4E-964C-3DA9C90858A4" }, { "criteria": "cpe:2.3:a:stafford.uklinux:libesmtp:1.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "19CDCC92-8EBC-48E3-B9B1-1CCA01C0E0E7" } ], "operator": "OR" } ] } ]