SSL Certificate Validation Flaw in KDE Konqueror Web Browser
CVE-2007-6591
Currently unrated
What is CVE-2007-6591?
The KDE Konqueror web browser has a vulnerability wherein accepting an SSL server certificate based on the Common Name (CN) in the Distinguished Name (DN) field leads the software to erroneously trust all domain names specified in the subjectAltName:dNSName fields. As a result, this flaw potentially allows remote attackers to deceive users into accepting invalid certificates for spoofed websites, posing a significant security risk as the product cannot effectively validate these additional fields.
