|
|
| |
|
| |
python-OpenSSL: certificate spoofing
| Package(s): | python-OpenSSL |
CVE #(s): | CVE-2013-4314
|
| Created: | September 13, 2013 |
Updated: | September 25, 2013 |
| Description: |
From the Mandriva advisory:
The string formatting of subjectAltName X509Extension instances in pyOpenSSL before 0.13.1 incorrectly truncated fields of the name when encountering a null byte, possibly allowing man-in-the-middle attacks through certificate spoofing (CVE-2013-4314). |
| Alerts: |
|
( Log in to post comments)
|
|
|