Date: Mon, 30 Apr 2012 19:34:48 -0400 From: Marc Deslauriers <marc.deslauriers@...onical.com> To: oss-security@...ts.openwall.com Cc: Vincent Untz <vuntz@...e.com> Subject: Re: CVE Request: libsoup 2.32.2 sets ssl trusted flag despite no verification On Tue, 2012-04-24 at 12:04 +0200, Ludwig Nussel wrote: > Hi, > > libsoup 2.32.2 does not verify certificates at all if an application does > not explicitly specify a file with trusted root CA's. Since that libsoup > version relies on the verification failure to clear the trust flag it > always considers ssl connections as trusted in that case. > > Reference: > https://bugzilla.novell.com/show_bug.cgi?id=758431 > Here is an upstream bug about the issue. https://bugzilla.gnome.org/show_bug.cgi?id=666280 Marc.
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.