Overview
Sun Microsystems uses a variety of X.509 keys signed by VeriSign to securevarious web sites. Among these certificates are two that were revoked on October 19, 2000. The certificate IDs for these revoked certificates are
3181 B12D C422 5DAC A340 CF86 2710 ABE6
and
1705 FB13 A22F 9AF3 C130 F562 6E12 504C
Description
|
Impact
Users who accept these certificates into their browser may inadvertently run malicious code signed by the compromised certificates. Any such code would appear to be from Sun Microsystems, thus creating a misleading sense of trust. |
Solution
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This document was written by Shawn Hernan.
Other Information
CVE IDs: | CVE-2000-0889 |
CERT Advisory: | CA-2000-19 |
Severity Metric: | 0.16 |
Date Public: | 2000-10-24 |
Date First Published: | 2000-12-12 |
Date Last Updated: | 2001-01-18 19:28 UTC |
Document Revision: | 8 |