LWN.net Logo

python-OpenSSL: certificate spoofing

Package(s):python-OpenSSL CVE #(s):CVE-2013-4314
Created:September 13, 2013 Updated:September 25, 2013
Description:

From the Mandriva advisory:

The string formatting of subjectAltName X509Extension instances in pyOpenSSL before 0.13.1 incorrectly truncated fields of the name when encountering a null byte, possibly allowing man-in-the-middle attacks through certificate spoofing (CVE-2013-4314).

Alerts:
Mandriva MDVSA-2013:233 2013-09-13
Mageia MGASA-2013-0277 2013-09-13
Fedora FEDORA-2013-15925 2013-09-21
Fedora FEDORA-2013-15881 2013-09-21
Ubuntu USN-1965-1 2013-09-23
Debian DSA-2763-1 2013-09-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds