« Volver al listado

CVE-2010-0744

Estado: ModificadaMedia (5.8)—

aMSN (aka Alvaro's Messenger) 0.98.3 and earlier, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof an MSN server via an arbitrary certificate.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-0744",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-04-20T15:30:00.317",
  "references": [
    {
      "url": "http://amsn.svn.sourceforge.net/viewvc/amsn/trunk/?view=log&pathrev=11991",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://amsn.svn.sourceforge.net/viewvc/amsn/trunk/amsn/proxy.tcl?r1=11886&r2=11991&pathrev=11991",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://amsn.svn.sourceforge.net/viewvc/amsn/trunk/amsn/sip.tcl?r1=11953&r2=11991&pathrev=11991",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://amsn.svn.sourceforge.net/viewvc/amsn/trunk/amsn/soap.tcl?r1=11891&r2=11991&pathrev=11991",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=572818",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041046.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041079.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://seclists.org/bugtraq/2009/Jun/239",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/35621",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/39796",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.opensource-archive.org/showthread.php?p=183821",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/03/10/4",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/04/01/4",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/35507",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/1109",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://amsn.svn.sourceforge.net/viewvc/amsn/trunk/?view=log&pathrev=11991",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://amsn.svn.sourceforge.net/viewvc/amsn/trunk/amsn/proxy.tcl?r1=11886&r2=11991&pathrev=11991",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://amsn.svn.sourceforge.net/viewvc/amsn/trunk/amsn/sip.tcl?r1=11953&r2=11991&pathrev=11991",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://amsn.svn.sourceforge.net/viewvc/amsn/trunk/amsn/soap.tcl?r1=11891&r2=11991&pathrev=11991",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=572818",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041046.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041079.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/bugtraq/2009/Jun/239",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/35621",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/39796",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.opensource-archive.org/showthread.php?p=183821",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/03/10/4",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/04/01/4",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/35507",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/1109",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "aMSN (aka Alvaro's Messenger) 0.98.3 and earlier, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof an MSN server via an arbitrary certificate."
    },
    {
      "lang": "es",
      "value": "aMSN (Alvaro's Messenger) v0.98.3 y anteriores, cuando SSL es utilizado, no verifica que el nombre de servidor concuerda con el nombre de dominio en el campo Nombre Común del sujeto (CN) o Nombre alternativo del sujeto del certificado X.509, lo que permite a atacantes realizar un ataque de \"man-in-the-middle\" (hombre en el medio) para suplantar un servidor MSN a través de un certificado de su elección."
    }
  ],
  "lastModified": "2026-06-16T23:16:45.960",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:alvaro:alvaros_messenger:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "530E2AC1-125E-4DA0-9DF1-4C57A0997821",
              "versionEndIncluding": "0.98.3"
            },
            {
              "criteria": "cpe:2.3:a:alvaro:alvaros_messenger:0.83:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2253FE27-0FB3-4AAB-AA2E-34E6B97C740F"
            },
            {
              "criteria": "cpe:2.3:a:alvaro:alvaros_messenger:0.90:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2025CF66-DD6D-4C6F-A29B-441B16D3E568"
            },
            {
              "criteria": "cpe:2.3:a:alvaro:alvaros_messenger:0.91:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EA0930E5-3489-4081-B794-3EE8317DB382"
            },
            {
              "criteria": "cpe:2.3:a:alvaro:alvaros_messenger:0.92:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AFF45563-B88E-4BE2-9B4C-5CFD623D8E97"
            },
            {
              "criteria": "cpe:2.3:a:alvaro:alvaros_messenger:0.93:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B66222D-3FB3-4369-B047-54BC0ADC4A60"
            },
            {
              "criteria": "cpe:2.3:a:alvaro:alvaros_messenger:0.94:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7E3512E6-FF13-4174-80DE-385F1F5D237F"
            },
            {
              "criteria": "cpe:2.3:a:alvaro:alvaros_messenger:0.95:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "286780E9-7232-4D6A-A44E-21BD25E7A915"
            },
            {
              "criteria": "cpe:2.3:a:alvaro:alvaros_messenger:0.96:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "37E9E9ED-40FC-4253-8701-8DC6072A8ACF"
            },
            {
              "criteria": "cpe:2.3:a:alvaro:alvaros_messenger:0.97:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B40C3229-2868-403A-80AE-D6F441299F5F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}