Netscape Navigator and Communicator...

- AV AC AU C I A
发布: 2000-05-10
修订: 2025-04-13

A vulnerability exists in the manner in which versions of Netscape Communicator up to, but not including, 4.73, validate SSL certificates. This vulnerability could make it possible for the integrity of an SSL connection to be compromised. For optimum security, Netscape should perform a match for a certificate for both the hostname and establish connections based on the name present in the certificate matching the name of any presently open connections. The example given in the Bugtraq posting outlined a possible way this could be utilized. An abridged, slightly clearer explanation: An attacker poisons a nameserver to redirect all connections to www.goodguy.com, normally 100.100.100.100, to 99.99.99.99, www.badguy.com. The attacker causes all normal http requests to return what they normally would on www.goodguy.com, even though a user attempting to contact www.goodguy.com hits www.badguy.com. Upon getting a hit to www.badguy.com, the attacker causes an SSL connection to be...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息