SSL Certificate Validation Flaw in KDE Konqueror Web Browser
CVE-2007-6591

Currently unrated

Key Information:

Vendor

Kde

Status
Vendor
CVE Published:
28 December 2007

What is CVE-2007-6591?

The KDE Konqueror web browser has a vulnerability wherein accepting an SSL server certificate based on the Common Name (CN) in the Distinguished Name (DN) field leads the software to erroneously trust all domain names specified in the subjectAltName:dNSName fields. As a result, this flaw potentially allows remote attackers to deceive users into accepting invalid certificates for spoofed websites, posing a significant security risk as the product cannot effectively validate these additional fields.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.