Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 13 Feb 2013 11:20:49 +1000
From: David Jorm <djorm@...hat.com>
To: oss-security@...ts.openwall.com
Subject: Re: CVE Request --  jakarta-commons-httpclient: Wildcard
 matching in SSL hostname verifier incorrect (a different issue than CVE-2012-5783)

On 02/13/2013 10:29 AM, Kurt Seifried wrote:
>> Please use CVE-2012-6127 for this issue.
> Ok I should have looked into this deeper, it looks like it may not be
> a security issue but I'm not 100% certain, so for now I will leave
> this, and if someone can show there is no security impact I'll reject
> it. Sorry for the mixup.

This bug will cause valid certificates to be rejected, but not for invalid certificates to be accepted. Please reject the CVE.

Thanks
David



Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.