Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6592 (Safari)

BugsAlert Home > CVE-2007-6592 (Safari)
 
 

Apple Safari 2, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regards the certificate as also accepted for all domain names in subjectAltName:dNSName fields, which makes it easier for remote attackers to trick a user into accepting an invalid certificate for a spoofed web site.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6592

Learn more about CVE-2007-6592 (Safari)
 
Tags: cve-2007-6592 safari

Related Items

      pfSense Cross-Site Scripting Vulnerabilities

      MySpace Pages Rigged with Bad Script

      PayPal Spam Warns of Fraud, Installs Worm Instead

      Vuln: Dizi Portali 'diziler.asp' SQL Injection Vulnerability

      DWdirectory "search" Parameter Remote SQL Injection Vulnerability

      TROJ_MDROPPER.WY

      vlbook Cross-Site Scripting and Local File Inclusion

 

Pixel