Back

MEDIUM

libESMTP: Multiple certificate validation flaws

Published Mar 31, 2010

Description

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Mar 31, 2010
Updated Aug 7, 2024
Reserved Mar 30, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Mar 3, 2010