|
Message-ID: <1319034455.2700.9.camel@mdlinux> Date: Wed, 19 Oct 2011 10:27:35 -0400 From: Marc Deslauriers <marc.deslauriers@...onical.com> To: coley@...us.mitre.org Cc: oss-security@...ts.openwall.com, security@...ntu.com, team@...urity.debian.org Subject: CVE Request: apt Hello, Could a CVE please be assigned to the following issue: Apt before 0.8.11 incorrectly handles the Verify-Host configuration option, resulting in a successful connection instead of a verification failure when the certificate host name doesn't match. See: http://bazaar.launchpad.net/~donkult/apt/sid/revision/2053.1.28 https://bugs.launchpad.net/ubuntu/+source/apt/+bug/868353 Thanks, Marc.
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.