CVE-2009-2700

Publication date 2 September 2009

Last updated 24 July 2024


Ubuntu priority

src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Status

Package Ubuntu Release Status
qt4-x11 9.10 karmic
Fixed 4.5.2-0ubuntu5
9.04 jaunty
Fixed 4.5.0-0ubuntu4.2
8.10 intrepid
Fixed 4.4.3-0ubuntu1.3
8.04 LTS hardy
Fixed 4.3.4-0ubuntu3.1
6.06 LTS dapper Ignored end of life

References

Related Ubuntu Security Notices (USN)

    • USN-829-1
    • Qt vulnerability
    • 10 September 2009

Other references