Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Certificate spoofing issue with Mozilla, Konqueror, Safari 2 Nov 19 2007 10:51PM
Kapetanakis Giannis (bilias edu physics uoc gr)
On Sun, 18 Nov 2007, Nils Toedtmann wrote:

> Mozilla based browsers (Firefox, Netscape, ...), Konqueror and Safari 2
> do not bind a user-approved webserver certificate to the originating
> domain name. This makes the user vulnerable to certificate spoofing by
> "subjectAltName:dNSName" extensions....

[ more ]  





 

Privacy Statement
Copyright 2008, SecurityFocus