oss-sec mailing list archives

Re: CVE requests: IO::Socket::SSL, cakephp, collectd, gnash, ocrodjvu, hypermail, libcloud, piwigo


From: Ludwig Nussel <ludwig.nussel () suse de>
Date: Thu, 9 Dec 2010 10:27:34 +0100

Josh Bressers wrote:
----- "Raphael Geissert" <geissert () debian org> wrote:
IO::Socket::SSL: unexpected fallback to VERIFY_NONE if certificate
file(s) 
are not specified.
http://bugs.debian.org/606058
http://secunia.com/advisories/42508/

CVE-2010-4334

There's a duplicate: CVE-2010-4501

cu
Ludwig

-- 
 (o_   Ludwig Nussel
 //\   
 V_/_  http://www.suse.de/
SUSE LINUX Products GmbH, GF: Markus Rex, HRB 16746 (AG Nuernberg)


Current thread: