CVE-2010-0744

aMSN (aka Alvaro's Messenger) 0.98.3 and earlier, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof an MSN server via an arbitrary certificate.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
VendorProductVersion
alvaroalvaros_messenger
𝑥
≤ 0.98.3
alvaroalvaros_messenger
0.83
alvaroalvaros_messenger
0.90
alvaroalvaros_messenger
0.91
alvaroalvaros_messenger
0.92
alvaroalvaros_messenger
0.93
alvaroalvaros_messenger
0.94
alvaroalvaros_messenger
0.95
alvaroalvaros_messenger
0.96
alvaroalvaros_messenger
0.97
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
amsn
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
dne
oneiric
not-affected
natty
not-affected
maverick
ignored
lucid
ignored
karmic
ignored
jaunty
ignored
intrepid
ignored
hardy
ignored
dapper
ignored
References