Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2009-2825

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2009-2825
Last Modified 17 Nov 2009 02:02:59
Published 10 Nov 2009 02:30:01
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2009-2825

Summary

Certificate Assistant in Apple Mac OS X before 10.6.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Vulnerable Systems

Operating System

  • Apple Mac Os X 10.0

  • Apple Mac Os X 10.0.0

  • Apple Mac Os X 10.0.1

  • Apple Mac Os X 10.0.2

  • Apple Mac Os X 10.0.3

  • Apple Mac Os X 10.0.4

  • Apple Mac Os X 10.1

  • Apple Mac Os X 10.1.0

  • Apple Mac Os X 10.1.1

  • Apple Mac Os X 10.1.2

  • Apple Mac Os X 10.1.3

  • Apple Mac Os X 10.1.4

  • Apple Mac Os X 10.1.5

  • Apple Mac Os X 10.2

  • Apple Mac Os X 10.2.0

  • Apple Mac Os X 10.2.1

  • Apple Mac Os X 10.2.2

  • Apple Mac Os X 10.2.3

  • Apple Mac Os X 10.2.4

  • Apple Mac Os X 10.2.5

  • Apple Mac Os X 10.2.6

  • Apple Mac Os X 10.2.7

  • Apple Mac Os X 10.2.8

  • Apple Mac Os X 10.3

  • Apple Mac Os X 10.3.0

  • Apple Mac Os X 10.3.1

  • Apple Mac Os X 10.3.2

  • Apple Mac Os X 10.3.3

  • Apple Mac Os X 10.3.4

  • Apple Mac Os X 10.3.5

  • Apple Mac Os X 10.3.6

  • Apple Mac Os X 10.3.7

  • Apple Mac Os X 10.3.8

  • Apple Mac Os X 10.3.9

  • Apple Mac Os X 10.4

  • Apple Mac Os X 10.4.0

  • Apple Mac Os X 10.4.1

  • Apple Mac Os X 10.4.10

  • Apple Mac Os X 10.4.11

  • Apple Mac Os X 10.4.2

  • Apple Mac Os X 10.4.3

  • Apple Mac Os X 10.4.4

  • Apple Mac Os X 10.4.5

  • Apple Mac Os X 10.4.6

  • Apple Mac Os X 10.4.7

  • Apple Mac Os X 10.4.8

  • Apple Mac Os X 10.4.9

  • Apple Mac Os X 10.5

  • Apple Mac Os X 10.5.0

  • Apple Mac Os X 10.5.1

  • Apple Mac Os X 10.5.2

  • Apple Mac Os X 10.5.3

  • Apple Mac Os X 10.5.4

  • Apple Mac Os X 10.5.5

  • Apple Mac Os X 10.5.6

  • Apple Mac Os X 10.5.7

  • Apple Mac Os X 10.5.8

  • Apple Mac Os X 10.6

  • Apple Mac Os X 10.6.1

  • Apple Mac Os X Server 10.0

  • Apple Mac Os X Server 10.0.0

  • Apple Mac Os X Server 10.0.1

  • Apple Mac Os X Server 10.0.2

  • Apple Mac Os X Server 10.0.3

  • Apple Mac Os X Server 10.0.4

  • Apple Mac Os X Server 10.1

  • Apple Mac Os X Server 10.1.0

  • Apple Mac Os X Server 10.1.1

  • Apple Mac Os X Server 10.1.2

  • Apple Mac Os X Server 10.1.3

  • Apple Mac Os X Server 10.1.4

  • Apple Mac Os X Server 10.1.5

  • Apple Mac Os X Server 10.2

  • Apple Mac Os X Server 10.2.0

  • Apple Mac Os X Server 10.2.1

  • Apple Mac Os X Server 10.2.2

  • Apple Mac Os X Server 10.2.3

  • Apple Mac Os X Server 10.2.4

  • Apple Mac Os X Server 10.2.5

  • Apple Mac Os X Server 10.2.6

  • Apple Mac Os X Server 10.2.7

  • Apple Mac Os X Server 10.2.8

  • Apple Mac Os X Server 10.3

  • Apple Mac Os X Server 10.3.0

  • Apple Mac Os X Server 10.3.1

  • Apple Mac Os X Server 10.3.2

  • Apple Mac Os X Server 10.3.3

  • Apple Mac Os X Server 10.3.4

  • Apple Mac Os X Server 10.3.5

  • Apple Mac Os X Server 10.3.6

  • Apple Mac Os X Server 10.3.7

  • Apple Mac Os X Server 10.3.8

  • Apple Mac Os X Server 10.3.9

  • Apple Mac Os X Server 10.4

  • Apple Mac Os X Server 10.4.0

  • Apple Mac Os X Server 10.4.1

  • Apple Mac Os X Server 10.4.10

  • Apple Mac Os X Server 10.4.11

  • Apple Mac Os X Server 10.4.2

  • Apple Mac Os X Server 10.4.3

  • Apple Mac Os X Server 10.4.4

  • Apple Mac Os X Server 10.4.5

  • Apple Mac Os X Server 10.4.6

  • Apple Mac Os X Server 10.4.7

  • Apple Mac Os X Server 10.4.8

  • Apple Mac Os X Server 10.4.9

  • Apple Mac Os X Server 10.5

  • Apple Mac Os X Server 10.5.0

  • Apple Mac Os X Server 10.5.1

  • Apple Mac Os X Server 10.5.2

  • Apple Mac Os X Server 10.5.3

  • Apple Mac Os X Server 10.5.4

  • Apple Mac Os X Server 10.5.5

  • Apple Mac Os X Server 10.5.6

  • Apple Mac Os X Server 10.5.7

  • Apple Mac Os X Server 10.5.8

  • Apple Mac Os X Server 10.6

  • Apple Mac Os X Server 10.6.1


References

BID - 36956

CONFIRM - http://support.apple.com/kb/HT3937

VUPEN - ADV-2009-3184

APPLE - APPLE-SA-2009-11-09-1

Related Patches

Apple 2009-11-09 Mac OS X v10.6.2 Update


Last Updated: 27 May 2016 10:51:02