|
|
Log in / Subscribe / Register

qpid-proton: TLS to plaintext downgrade

Package(s):qpid-proton CVE #(s):CVE-2016-2166
Created:April 15, 2016 Updated:April 20, 2016
Description: From the Red Hat bugzilla entry:

Messaging applications using the Proton Python API to provision an SSL/TLS encrypted TCP connection may actually instantiate a non-encrypted connection without notice if SSL support is unavailable. This will result in all messages being sent in the clear without the knowledge of the user.

Alerts:
Fedora FEDORA-2016-e6e8436b98 qpid-proton 2016-04-15

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds