Mozilla based browsers (Firefox, Netscape, etc), Konqueror and Safari 2 do not bind a user-approved webserver certificate to the originating domain name. This makes the user vulnerable to certificate spoofing by “subjectAltName:dNSName” extensions.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/61138/certspoof.txt
Source: https://packetstormsecurity.com/files/61138/certspoof.txt.html

