CVE-2011-3366

Publication date 29 November 2011

Last updated 24 July 2024


Ubuntu priority

Description

Rekonq 0.7.0 and earlier does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.

Read the notes from the security team

Status

Package Ubuntu Release Status
rekonq 11.10 oneiric
Not affected
11.04 natty
Not affected
10.10 maverick
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy Not in release

Notes


jdstrand

Ubuntu 11.04 and earlier uses KSslInfoDialog from kdelibs