|
|
Subscribe / Log in / New account

mercurial: man-in-the-middle attack

Package(s):mercurial CVE #(s):CVE-2010-4237
Created:December 7, 2010 Updated:December 8, 2010
Description: From the Novell bugzilla:

a security flaw was found in the way Mercurial handled subject Common Name field of the provided certificate (the check if the commonName in the received certificate matches the requested hostname was not performed). An attacker, able to get a carefully-crafted certificate signed by a Certificate Authority could use the certificate during a man-in-the-middle attack and potentially confuse Mercurial into accepting it by mistake.

Alerts:
openSUSE openSUSE-SU-2010:1029-1 mercurial 2010-12-07

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds