Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
neon 加密问题漏洞
Vulnerability Description
neon是一个带有C接口的HTTP/1.1和WebDAV客户端库。 neon 0.28.6之前版本中存在加密问题漏洞,该漏洞源于OpenSSL或GnuTLS被使用时,程序没有正确处理X.509证书的Common Name (CN)字段域名中的“”字符。攻击者可借助特制的凭证利用该漏洞获取敏感信息或修改加密通信。
CVSS Information
N/A
Vulnerability Type
N/A