Candidate: CVE-2009-2417 PublicDate: 2009-08-14 15:16:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2417 https://ubuntu.com/security/notices/USN-818-1 https://ubuntu.com/security/notices/USN-1158-1 Description: lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. Ubuntu-Description: sbeattie> hardy's patch for this issue was added to the end of the quilt series; unfortunately, the build system is quirky and pushes up patches by a name, thus the patch for this was not getting applied at build time. Fixed in usn-1158-1. Notes: Bugs: Priority: medium Discovered-by: Assigned-to: kees CVSS: Patches_curl: upstream_curl: released (7.19.6) dapper_curl: released (7.15.1-1ubuntu3.2) hardy_curl: released (7.18.0-1ubuntu2.3) intrepid_curl: released (7.18.2-1ubuntu4.4) jaunty_curl: released (7.18.2-8ubuntu4.1) devel_curl: released (7.19.5-1ubuntu2)