MEDIUM · 4.0

CVE-2008-2809

Mozilla 1.9 M8 and earlier, Mozilla Firefox 2 before 2.0.0.15, SeaMonkey 1.1.5 and other versions before 1.1.10, Netscape 9.0, and other Mozilla-based web browsers, when a user accepts an SSL server c...

Vulnerability Description

Mozilla 1.9 M8 and earlier, Mozilla Firefox 2 before 2.0.0.15, SeaMonkey 1.1.5 and other versions before 1.1.10, Netscape 9.0, and other Mozilla-based web browsers, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regard the certificate as also accepted for all domain names in subjectAltName:dNSName fields, which makes it easier for remote attackers to trick a user into accepting an invalid certificate for a spoofed web site.

CVSS Score

4.0

MEDIUM

AV:N/AC:H/Au:N/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
MozillaFirefox2.0.0.1
MozillaGeckb<= 1.9
MozillaSeamonkey<= 1.0.9
NetscapeNavigator9.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-2809?

CVE-2008-2809 is a vulnerability with a CVSS score of 4.0 (MEDIUM). Mozilla 1.9 M8 and earlier, Mozilla Firefox 2 before 2.0.0.15, SeaMonkey 1.1.5 and other versions before 1.1.10, Netscape 9.0, and other Mozilla-based web browsers, when a user accepts an SSL server c...

How severe is CVE-2008-2809?

CVE-2008-2809 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-2809?

Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox, Mozilla Geckb, Mozilla Seamonkey, Netscape Navigator.