|
Message-ID: <511AEA71.8040008@redhat.com> Date: Wed, 13 Feb 2013 11:20:49 +1000 From: David Jorm <djorm@...hat.com> To: oss-security@...ts.openwall.com Subject: Re: CVE Request -- jakarta-commons-httpclient: Wildcard matching in SSL hostname verifier incorrect (a different issue than CVE-2012-5783) On 02/13/2013 10:29 AM, Kurt Seifried wrote: >> Please use CVE-2012-6127 for this issue. > Ok I should have looked into this deeper, it looks like it may not be > a security issue but I'm not 100% certain, so for now I will leave > this, and if someone can show there is no security impact I'll reject > it. Sorry for the mixup. This bug will cause valid certificates to be rejected, but not for invalid certificates to be accepted. Please reject the CVE. Thanks David
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.