Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenLDAP 信任管理问题漏洞
Vulnerability Description
OpenLDAP是美国OpenLDAP基金会的一个轻型目录访问协议(LDAP)的开源实现。 OpenLDAP的libraries/libldap/tls_o.c在OpenSSL中运行时,没有适当地处理X.509证书的一个主题的常用名字段中的域名的“”字符。中间人攻击者可借助特制的证书欺骗任意SSL服务器,该证书由合法证书权威机构颁发。
CVSS Information
N/A
Vulnerability Type
N/A