Oval Definition:oval:org.opensuse.security:def:20101192
Revision Date:2022-05-20Version:1
Title:CVE-2010-1192
Description:

libESMTP, probably 1.0.4 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2010-1192
Mitre CVE-2010-1192
SUSE CVE-2010-1192
openSUSE-SU-2010:0220-1
openSUSE-SU-2010:0220-1
SUSE-SR:2010:011
SUSE-SR:2010:011
Platform(s):openSUSE 11.0
openSUSE 11.1
openSUSE 11.2
SUSE Linux Enterprise SDK 11 GA
SUSE Linux Enterprise Server 11
SUSE Linux Enterprise Server 11 GA
SUSE Linux Enterprise Server for SAP Applications 11
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Server 11 is installed
  • AND libesmtp-1.0.4-157.15 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 11 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 is installed
  • AND libesmtp-1.0.4-157.15.1 is installed
  • BACK