CVE-2009-3455
Apple Safari < 4.0.3 - SSL Server Spoofing via Null Byte in X.509 Certificate CN Field
Title source: llmDescription
Apple Safari, possibly before 4.0.3, on Mac OS X does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
References (2)
Core 2
Core References
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/36477
Various Sources x_refsource_misc
http://www.networkworld.com/news/2009/091709-microsoft-ie-security-hole.html
Scores
EPSS
0.0058
EPSS Percentile
44.2%
Details
CWE
CWE-310
Status
published
Products (40)
apple/safari
0.8
apple/safari
0.9
apple/safari
1.0
apple/safari
1.0.0
apple/safari
1.0b1
apple/safari
1.1
apple/safari
1.2
apple/safari
1.2.0
apple/safari
1.2.1
apple/safari
1.2.2
... and 30 more
Published
Sep 29, 2009
Tracked Since
Feb 18, 2026