CVE-2010-1192

libESMTP, probably 1.0.4 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
canonicalCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
VendorProductVersion
stafford.uklinuxlibesmtp
𝑥
≤ 1.0.4
stafford.uklinuxlibesmtp
0.1
stafford.uklinuxlibesmtp
0.1:a
stafford.uklinuxlibesmtp
0.2
stafford.uklinuxlibesmtp
0.3
stafford.uklinuxlibesmtp
0.4
stafford.uklinuxlibesmtp
0.5
stafford.uklinuxlibesmtp
0.6
stafford.uklinuxlibesmtp
0.6:a
stafford.uklinuxlibesmtp
0.6.1
stafford.uklinuxlibesmtp
0.7.0
stafford.uklinuxlibesmtp
0.7.1
stafford.uklinuxlibesmtp
0.8.0
stafford.uklinuxlibesmtp
0.8.1
stafford.uklinuxlibesmtp
0.8.2
stafford.uklinuxlibesmtp
0.8.3
stafford.uklinuxlibesmtp
0.8.4
stafford.uklinuxlibesmtp
0.8.5
stafford.uklinuxlibesmtp
0.8.6
stafford.uklinuxlibesmtp
0.8.7
stafford.uklinuxlibesmtp
0.8.8
stafford.uklinuxlibesmtp
0.8.9
stafford.uklinuxlibesmtp
0.8.10
stafford.uklinuxlibesmtp
0.8.10:p1
stafford.uklinuxlibesmtp
0.8.11
stafford.uklinuxlibesmtp
0.8.12
stafford.uklinuxlibesmtp
1.0
stafford.uklinuxlibesmtp
1.0:rc1
stafford.uklinuxlibesmtp
1.0.1
stafford.uklinuxlibesmtp
1.0.2
stafford.uklinuxlibesmtp
1.0.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libesmtp
bullseye
1.0.6-4.3
fixed
lenny
no-dsa
bookworm
1.1.0-3.1~deb12u1
fixed
sid
1.1.0-3.2
fixed
trixie
1.1.0-3.2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libesmtp
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
ignored
karmic
ignored
jaunty
ignored
intrepid
ignored
hardy
ignored
dapper
ignored
Common Weakness Enumeration