Tracker / CVE-2002-0862
CVE-2002-0862
Media 6.8
The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.
Prodotti e versioni affette
| microsoft | internet_explorer |
|---|---|
| microsoft | office |
| microsoft | outlook_express |
| microsoft | windows_2000 |
| microsoft | windows_98 |
| microsoft | windows_98se |
| microsoft | windows_me |
| microsoft | windows_nt |
| microsoft | windows_xp |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.