Oval Definition:oval:org.opensuse.security:def:20093639
Revision Date:2022-06-30Version:1
Title:CVE-2009-3639
Description:

The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, which allows remote attackers to bypass intended client-hostname restrictions via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2009-3639
SUSE CVE-2009-3639
Platform(s):openSUSE Tumbleweed
Product(s):
Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • proftpd-1.3.5b-2.5 is installed
  • OR proftpd-devel-1.3.5b-2.5 is installed
  • OR proftpd-doc-1.3.5b-2.5 is installed
  • OR proftpd-lang-1.3.5b-2.5 is installed
  • OR proftpd-ldap-1.3.5b-2.5 is installed
  • OR proftpd-mysql-1.3.5b-2.5 is installed
  • OR proftpd-pgsql-1.3.5b-2.5 is installed
  • OR proftpd-radius-1.3.5b-2.5 is installed
  • OR proftpd-sqlite-1.3.5b-2.5 is installed
  • BACK