Unrated severityNVD Advisory· Published Sep 8, 2009· Updated Apr 23, 2026
CVE-2009-2702
CVE-2009-2702
Description
KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- secunia.com/advisories/36468nvdVendor Advisory
- www.vupen.com/english/advisories/2009/2532nvdVendor Advisory
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- bugzilla.redhat.com/show_bug.cginvd
News mentions
0No linked articles in our index yet.