The software performs a comparison that only examines a portion
of a factor before determining whether there is a match, such as a substring,
leading to resultant weaknesses.
Extended Description
For example, an attacker might succeed in authentication by providing a
small password that matches the associated portion of the larger, correct
password.
Web browser only checks the hostname portion of a
certificate when the hostname portion of the URI is not a fully qualified
domain name (FQDN), which allows remote attackers to spoof trusted
certificates.