CVE-2010-0744

aMSN (aka Alvaro's Messenger) 0.98.3 and earlier, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof an MSN server via an arbitrary certificate.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:alvaro:alvaros_messenger:*:*:*:*:*:*:*:*
cpe:2.3:a:alvaro:alvaros_messenger:0.83:*:*:*:*:*:*:*
cpe:2.3:a:alvaro:alvaros_messenger:0.90:*:*:*:*:*:*:*
cpe:2.3:a:alvaro:alvaros_messenger:0.91:*:*:*:*:*:*:*
cpe:2.3:a:alvaro:alvaros_messenger:0.92:*:*:*:*:*:*:*
cpe:2.3:a:alvaro:alvaros_messenger:0.93:*:*:*:*:*:*:*
cpe:2.3:a:alvaro:alvaros_messenger:0.94:*:*:*:*:*:*:*
cpe:2.3:a:alvaro:alvaros_messenger:0.95:*:*:*:*:*:*:*
cpe:2.3:a:alvaro:alvaros_messenger:0.96:*:*:*:*:*:*:*
cpe:2.3:a:alvaro:alvaros_messenger:0.97:*:*:*:*:*:*:*

History

No history.

Information

Published : 2010-04-20 15:30

Updated : 2023-12-10 11:03


NVD link : CVE-2010-0744

Mitre link : CVE-2010-0744

CVE.ORG link : CVE-2010-0744


JSON object : View

Products Affected

alvaro

  • alvaros_messenger
CWE
CWE-287

Improper Authentication