CVE-2011-3365
Publication date 3 October 2011
Last updated 24 July 2024
Ubuntu priority
The KDE SSL Wrapper (KSSL) API in KDE SC 4.6.0 through 4.7.1, and possibly earlier versions, does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.
From the Ubuntu Security Team
Tim Brown discovered that KSSL in KDE-Libs did not properly perform input validation when displaying the common name (CN) for an SSL certificate. An attacker could exploit this to spoof the common name which could be used in an attack to trick the user into accepting a fraudulent certificate.
Notes
References
Related Ubuntu Security Notices (USN)
- USN-1248-1
- KDE-Libs vulnerability
- 25 October 2011