LWN.net Logo

python: SSL hostname check bypass

Package(s):python CVE #(s):CVE-2013-4328
Created:August 19, 2013 Updated:August 21, 2013
Description:

From the Mageia advisory:

Ryan Sleevi of the Google Chrome Security Team has discovered that Python's SSL module doesn't handle NULL bytes inside subjectAltNames general names. This could lead to a breach when an application uses ssl.match_hostname() to match the hostname againt the certificate's subjectAltName's dNSName general names. (CVE-2013-4328).

Alerts: (No alerts in the database for this vulnerability)

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds