CVE-2009-3490

GNU Wget before 1.12 does not properly handle a '\0' character in a domain name in the Common Name field of an X.509 certificate, which allows man-in-the-middle remote attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
VendorProductVersion
gnuwget
𝑥
≤ 1.11.4
gnuwget
1.5.3
gnuwget
1.6
gnuwget
1.7
gnuwget
1.7.1
gnuwget
1.8
gnuwget
1.8.1
gnuwget
1.9
gnuwget
1.9.1
gnuwget
1.10
gnuwget
1.10.1
gnuwget
1.10.2
gnuwget
1.11
gnuwget
1.11.1
gnuwget
1.11.2
gnuwget
1.11.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
wget
bullseye
1.21-1+deb11u1
fixed
bookworm
1.21.3-1
fixed
sid
1.24.5-2
fixed
trixie
1.24.5-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
wget
jaunty
Fixed 1.11.4-2ubuntu1.1
released
intrepid
Fixed 1.11.4-1ubuntu1.1
released
hardy
Fixed 1.10.2-3ubuntu1.1
released
dapper
Fixed 1.10.2-1ubuntu1.1
released
Common Weakness Enumeration