Vulnerability CVE-2010-1194: Information

Description

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.

Severity: MEDIUM (6.8)

Published: March 31, 2010
Modified: May 22, 2010
Error type identifier: CWE-310

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:stafford.uklinux:libesmtp:0.6:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.2:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.7.1:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.8.3:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.8.0:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:1.0.1:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.1:a:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.8.9:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.5:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.8.6:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:1.0.3:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.8.10:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.6.1:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:1.0.3:r1:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.8.4:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.3:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:1.0:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:1.0:rc1:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.6:a:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.7.0:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.8.5:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.4:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.8.8:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:1.0.2:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.8.10:p1:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.8.12:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.8.1:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.8.2:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.8.7:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.8.11:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:1.0.4:*:*:*:*:*:*:*

      cpe:2.3:a:stafford.uklinux:libesmtp:0.1:-:*:*:*:*:*:*