CVE-2010-1194

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
canonicalCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
VendorProductVersion
stafford.uklinuxlibesmtp
0.1
stafford.uklinuxlibesmtp
0.1:a
stafford.uklinuxlibesmtp
0.2
stafford.uklinuxlibesmtp
0.3
stafford.uklinuxlibesmtp
0.4
stafford.uklinuxlibesmtp
0.5
stafford.uklinuxlibesmtp
0.6
stafford.uklinuxlibesmtp
0.6:a
stafford.uklinuxlibesmtp
0.6.1
stafford.uklinuxlibesmtp
0.7.0
stafford.uklinuxlibesmtp
0.7.1
stafford.uklinuxlibesmtp
0.8.0
stafford.uklinuxlibesmtp
0.8.1
stafford.uklinuxlibesmtp
0.8.2
stafford.uklinuxlibesmtp
0.8.3
stafford.uklinuxlibesmtp
0.8.4
stafford.uklinuxlibesmtp
0.8.5
stafford.uklinuxlibesmtp
0.8.6
stafford.uklinuxlibesmtp
0.8.7
stafford.uklinuxlibesmtp
0.8.8
stafford.uklinuxlibesmtp
0.8.9
stafford.uklinuxlibesmtp
0.8.10
stafford.uklinuxlibesmtp
0.8.10:p1
stafford.uklinuxlibesmtp
0.8.11
stafford.uklinuxlibesmtp
0.8.12
stafford.uklinuxlibesmtp
1.0
stafford.uklinuxlibesmtp
1.0:rc1
stafford.uklinuxlibesmtp
1.0.1
stafford.uklinuxlibesmtp
1.0.2
stafford.uklinuxlibesmtp
1.0.3
stafford.uklinuxlibesmtp
1.0.3:r1
stafford.uklinuxlibesmtp
1.0.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libesmtp
bullseye
1.0.6-4.3
fixed
bookworm
1.1.0-3.1~deb12u1
fixed
sid
1.1.0-3.2
fixed
trixie
1.1.0-3.2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libesmtp
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
ignored
jaunty
ignored
intrepid
ignored
hardy
ignored
dapper
ignored
Common Weakness Enumeration