← Back

CVE-2007-6591

nvd nist
Published: Dec 28, 2007Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

KDE Konqueror 3.5.5 and 3.95.00, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regards the certificate as also accepted for all domain names in subjectAltName:dNSName fields, even though these fields cannot be examined in the product, which makes it easier for remote attackers to trick a user into accepting an invalid certificate for a spoofed web site.

Affected (2)

Products: Kde: Konqueror
1 product
Konqueror
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Kde
Version 3.5.5
Version 3.95.00

Timeline

No history available yet.