exploits , vulnerabilities , articles , ProFTPD mod_tls Module NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
| Title |
ProFTPD mod_tls Module NULL Character CA SSL Certificate Validation Security Bypass Vulnerability |
| Published |
2009-10-23-12:00AM |
| Updated |
2009-10-23-08:58PM |
| Class |
Design Error |
| CVE |
CVE-2009-3639 |
| Remote |
Yes |
| Local |
No |
| Credit |
TJ Saunders |
| Vulnerable |
ProFTPD Project ProFTPD 1.3.2 rc3 ProFTPD Project ProFTPD 1.3.2 rc2 ProFTPD Project ProFTPD 1.3.2 ProFTPD Project ProFTPD 1.3.1 ProFTPD Project ProFTPD 1.3 rc3 ProFTPD Project ProFTPD 1.3 a ProFTPD Project ProFTPD 1.3 .0rc2 ProFTPD Project ProFTPD 1.3 .0rc1 ProFTPD Project ProFTPD 1.3 ProFTPD Project ProFTPD 1.2.10 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia64 Debian Linux 3.1 ia32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 ProFTPD Project ProFTPD 1.2.9 rc3 ProFTPD Project ProFTPD 1.2.9 rc2 ProFTPD Project ProFTPD 1.2.9 rc1 ProFTPD Project ProFTPD 1.2.9 MandrakeSoft Linux Mandrake 10.0 OpenPKG OpenPKG 2.0 OpenPKG OpenPKG 1.3 OpenPKG OpenPKG Current Slackware Linux 9.1 Slackware Linux 9.0 Slackware Linux 8.1 Slackware Linux current ProFTPD Project ProFTPD 1.2.8 rc2 ProFTPD Project ProFTPD 1.2.8 rc1 ProFTPD Project ProFTPD 1.2.8 Slackware Linux 9.0 Slackware Linux 8.1 Slackware Linux current ProFTPD Project ProFTPD 1.2.7 rc3 ProFTPD Project ProFTPD 1.2.7 rc2 ProFTPD Project ProFTPD 1.2.7 rc1 ProFTPD Project ProFTPD 1.2.7 Sun Cobalt Qube 3 ProFTPD Project ProFTPD 1.2.6 ProFTPD Project ProFTPD 1.2.5 rc1 ProFTPD Project ProFTPD 1.2.5 ProFTPD Project ProFTPD 1.2.4 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia64 Debian Linux 3.0 ia32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 ProFTPD Project ProFTPD 1.2.3 ProFTPD Project ProFTPD 1.2.2 rc3 ProFTPD Project ProFTPD 1.2.2 rc1 ProFTPD Project ProFTPD 1.2.2 ProFTPD Project ProFTPD 1.2.1 ProFTPD Project ProFTPD 1.2 pre9 ProFTPD Project ProFTPD 1.2 pre8 ProFTPD Project ProFTPD 1.2 pre7 ProFTPD Project ProFTPD 1.2 pre6 ProFTPD Project ProFTPD 1.2 pre5 ProFTPD Project ProFTPD 1.2 pre4 ProFTPD Project ProFTPD 1.2 pre3 ProFTPD Project ProFTPD 1.2 pre2 ProFTPD Project ProFTPD 1.2 pre11 ProFTPD Project ProFTPD 1.2 pre10 ProFTPD Project ProFTPD 1.2 pre1 ProFTPD Project ProFTPD 1.2 .0rc3 Conectiva Linux 7.0 Conectiva Linux 6.0 Conectiva Linux 5.1 Conectiva Linux 5.0 Conectiva Linux graficas Conectiva Linux ecommerce MandrakeSoft Linux Mandrake 8.1 ia64 MandrakeSoft Linux Mandrake 8.1 MandrakeSoft Linux Mandrake 8.0 ppc MandrakeSoft Linux Mandrake 8.0 MandrakeSoft Linux Mandrake 7.2 ProFTPD Project ProFTPD 1.2 .0rc2 ProFTPD Project ProFTPD 1.2 .0rc1 ProFTPD Project ProFTPD 1.2 Cobalt Qube 3.0 Cobalt Qube 2.0 Cobalt RaQ 3.0 Cobalt RaQ 2.0 Cobalt RaQ 1.1
|
| Not Vulnerable |
ProFTPD Project ProFTPD 1.3.3 rc2 ProFTPD Project ProFTPD 1.3.2b
|
| Code |
Attackers use man-in-the-middle attacks to exploit this issue. |
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Sat, 28 Nov 2009 23:01:02 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
peactur wwwvideopo 67968.com 200 /compo ricargbook proftpd 1. www.gov.co wap free s SEXY girl BRAZERSSEX 20829 bscindia.c picture y ems blog.sina. Zoosex mov sexo video tamilactre Crack+Data Doctorsex 6d2.cn www.donkys GET /u league www.playbo Windows200 dragon wet+pusy phpschedul netjuke CMS is Fre www.sexiph sex video xoit naked gir licken.net sexe/..com mahjong an 7,o Www.samira free *** 8 www.world Www.red-li dnsmasq sexy/movie fucking vi Pakistanse vuln/explo Wap.keez m www.887692
|