CVE-2009-2700
Publication date 2 September 2009
Last updated 24 July 2024
Ubuntu priority
src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly handle a ‘\0’ character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Status
Package | Ubuntu Release | Status |
---|---|---|
qt4-x11 | 9.10 karmic |
Fixed 4.5.2-0ubuntu5
|
9.04 jaunty |
Fixed 4.5.0-0ubuntu4.2
|
|
8.10 intrepid |
Fixed 4.4.3-0ubuntu1.3
|
|
8.04 LTS hardy |
Fixed 4.3.4-0ubuntu3.1
|
|
6.06 LTS dapper | Ignored end of life |