|
Message-ID: <CAGKxTURUKjUkjXOKvT+MdYZTXyVQq6fQEj2tsxyXhXE+XxvVmw@mail.gmail.com> Date: Fri, 21 Apr 2023 09:18:33 +0930 From: Christian Heinrich <christian.heinrich@...h.id.au> To: oss-security@...ts.openwall.com Cc: sjn@....org Subject: Re: Perl's HTTP::Tiny has insecure TLS cert default, affecting CPAN.pm and other modules Stig, On Wed, 19 Apr 2023 at 01:24, Stig Palmquist <stig@...g.io> wrote: > ... and more. We have generated a list of over 300 potentially affected > CPAN distributions. The responsibility for this fix is therefore with the maintainers of the CPAN modules who accepted the residual risk as documented at https://metacpan.org/pod/HTTP::Tiny#SSL-SUPPORT rather than HTTP:Tiny itself. -- Regards, Christian Heinrich http://cmlh.id.au/contact
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.