CVE-2003-0370

Konqueror Embedded & KDE <2.2.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.

References (8)

Core 8
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2003-192.html
Mailing List mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2003-May/004983.html
Various Sources vendor-advisory x_refsource_turbo
http://www.turbolinux.com/security/TLSA-2003-36.txt
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2003-193.html
Vendor Advisory mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/320707
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2003/dsa-361
Patch, Vendor Advisory x_refsource_confirm
http://www.kde.org/info/security/advisory-20030602-1.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/7520

Scores

EPSS 0.0094
EPSS Percentile 76.5%

Details

Status published
Products (9)
apple/safari 1.0 beta (2 CPE variants)
kde/kde < 2.2.2
kde/konqueror_embedded 0.1
redhat/linux 7.1
redhat/linux 7.2
turbolinux/turbolinux_server 7.0
turbolinux/turbolinux_server 8.0
turbolinux/turbolinux_workstation 7.0
turbolinux/turbolinux_workstation 8.0
Published Jun 16, 2003
Tracked Since Feb 18, 2026