CVE-2016-7099

Source
https://cve.org/CVERecord?id=CVE-2016-7099
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-7099.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-7099
Downstream
Related
Published
2016-10-10T16:59:01.277Z
Modified
2026-05-17T11:55:05.381720852Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

Database specific
{
    "unresolved_ranges": [
        {
            "vendor_product": "suse:linux_enterprise",
            "extracted_events": [
                {
                    "last_affected": "12.0"
                }
            ],
            "source": "CPE_FIELD",
            "cpes": [
                "cpe:2.3:o:suse:linux_enterprise:12.0:*:*:*:*:*:*:*"
            ]
        }
    ]
}
References

Affected packages