Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Thu, 3 Sep 2009 16:45:47 +0200
From: Tomas Hoger <>
To: OSS Security <>
Cc: "Steven M. Christey" <>
Subject: More CVE-2009-2408 like issues


CVE-2009-2408-like problems were identified and fixed in some more

wget - bunch of relevant links are available in here:

mutt, when using OpenSSL, fixed via:
This only applies to 1.5.19 and later, as no name check was done in
earlier versions when OpenSSL was used for crypto, which is a problem
by itself:

Qt got CVE-2009-2700, earlier versions of KDE use own crypto wrapper
implemented in kdelibs, which is affected too:

OpenLDAP upstream did some changes that addressed this in OpenSSL
wrapping code, along with change related to handling of multiple CNs:
They also changed GnuTLS code to check the last CN instead of the first
one, but this was not affected by CVE-2009-2408-like problems:
NSS wrapper was re-written too to do name checking itself and not rely
on NSS (CVE-2009-2408 should likely apply here directly and patched
NSS should be sufficient to address null prefix issue in this case;
I've not tested though, do your own tests if you build OpenLDAP with

Tomas Hoger / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.