Name | CVE-2010-3900 |
Description | Midori before 0.2.5, when WebKitGTK+ before 1.1.14 or LibSoup before 2.29.91 is used, does not verify X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary https web sites via a crafted server certificate, a related issue to CVE-2010-3312. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 607497 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
midori (PTS) | stretch | 0.5.11-ds1-4 | fixed |
buster | 7.0-2 | fixed | |
bullseye | 7.0-2.1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
midori | source | (unstable) | 0.2.7-1.1 | unimportant | 607497 |
Current Midori SSL support is very limited
Midori should not be used if SSL support is important to you