oss-sec mailing list archives
Re: [ANNOUNCE] CVE-2018-11775: ActiveMQ Client - Missing TLS Hostname Verification
From: Solar Designer <solar () openwall com>
Date: Mon, 10 Sep 2018 21:07:17 +0200
Christopher, On Mon, Sep 10, 2018 at 02:40:05PM -0400, Christopher Shannon wrote:
Please check the following document and see if you're affected by the issue. http://activemq.apache.org/security-advisories.data/CVE-2018-11775-announcement.txt
Thank you for bringing this to oss-security. However, please be aware that including essential information only by reference is against list content guidelines here: https://oss-security.openwall.org/wiki/mailing-lists/oss-security#list-content-guidelines which include: "At least the most essential part of your message (e.g., vulnerability detail and/or exploit) should be directly included in the message itself (and in plain text), rather than only included by reference to an external resource. Posting links to relevant external resources as well is acceptable, but posting only links is not. Your message should remain valuable even with all of the external resources gone." To correct this, I've attached the entire text file from the URL above, with the typo corrected as you mentioned in your follow-up message. Alexander
Attachment:
CVE-2018-11775-announcement.txt
Description:
Current thread:
- [ANNOUNCE] CVE-2018-11775: ActiveMQ Client - Missing TLS Hostname Verification Christopher Shannon (Sep 10)
- Re: [ANNOUNCE] CVE-2018-11775: ActiveMQ Client - Missing TLS Hostname Verification Christopher Shannon (Sep 10)
- Re: [ANNOUNCE] CVE-2018-11775: ActiveMQ Client - Missing TLS Hostname Verification Solar Designer (Sep 10)