Unrated severityNVD Advisory· Published Apr 20, 2010· Updated Apr 29, 2026
CVE-2010-0744
CVE-2010-0744
Description
aMSN (aka Alvaro's Messenger) 0.98.3 and earlier, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof an MSN server via an arbitrary certificate.
Affected products
10cpe:2.3:a:alvaro:alvaros_messenger:*:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:alvaro:alvaros_messenger:*:*:*:*:*:*:*:*range: <=0.98.3
- cpe:2.3:a:alvaro:alvaros_messenger:0.83:*:*:*:*:*:*:*
- cpe:2.3:a:alvaro:alvaros_messenger:0.90:*:*:*:*:*:*:*
- cpe:2.3:a:alvaro:alvaros_messenger:0.91:*:*:*:*:*:*:*
- cpe:2.3:a:alvaro:alvaros_messenger:0.92:*:*:*:*:*:*:*
- cpe:2.3:a:alvaro:alvaros_messenger:0.93:*:*:*:*:*:*:*
- cpe:2.3:a:alvaro:alvaros_messenger:0.94:*:*:*:*:*:*:*
- cpe:2.3:a:alvaro:alvaros_messenger:0.95:*:*:*:*:*:*:*
- cpe:2.3:a:alvaro:alvaros_messenger:0.96:*:*:*:*:*:*:*
- cpe:2.3:a:alvaro:alvaros_messenger:0.97:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
15- amsn.svn.sourceforge.net/viewvc/amsn/trunk/nvdVendor Advisory
- amsn.svn.sourceforge.net/viewvc/amsn/trunk/amsn/proxy.tclnvdVendor Advisory
- amsn.svn.sourceforge.net/viewvc/amsn/trunk/amsn/sip.tclnvdVendor Advisory
- amsn.svn.sourceforge.net/viewvc/amsn/trunk/amsn/soap.tclnvdVendor Advisory
- secunia.com/advisories/35621nvdVendor Advisory
- bugs.debian.org/cgi-bin/bugreport.cginvd
- lists.fedoraproject.org/pipermail/package-announce/2010-May/041046.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2010-May/041079.htmlnvd
- seclists.org/bugtraq/2009/Jun/239nvd
- secunia.com/advisories/39796nvd
- www.opensource-archive.org/showthread.phpnvd
- www.openwall.com/lists/oss-security/2010/03/10/4nvd
- www.openwall.com/lists/oss-security/2010/04/01/4nvd
- www.securityfocus.com/bid/35507nvd
- www.vupen.com/english/advisories/2010/1109nvd
News mentions
0No linked articles in our index yet.