oss-sec mailing list archives

Re: CVE Request -- jakarta-commons-httpclient: Wildcard matching in SSL hostname verifier incorrect (a different issue than CVE-2012-5783)


From: David Jorm <djorm () redhat com>
Date: Wed, 13 Feb 2013 11:20:49 +1000

On 02/13/2013 10:29 AM, Kurt Seifried wrote:
Please use CVE-2012-6127 for this issue.
Ok I should have looked into this deeper, it looks like it may not be
a security issue but I'm not 100% certain, so for now I will leave
this, and if someone can show there is no security impact I'll reject
it. Sorry for the mixup.

This bug will cause valid certificates to be rejected, but not for invalid certificates to be accepted. Please reject 
the CVE.

Thanks
David




Current thread: