Bug#722055: python-openssl: CVE-2013-4314: hostname check bypassing vulnerability

2013-09-12 Thread Salvatore Bonaccorso
Hello Sandro Are you working on the updates for this issues? The Security Team also has pyopenssl on the needs DSA list: Could you also prepare packages targetting squeeze-security and wheezy-security? Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org

Bug#722055: python-openssl: CVE-2013-4314: hostname check bypassing vulnerability

2013-09-07 Thread Henri Salo
Package: python-openssl Version: 0.13-2+b2 Severity: important Tags: security, fixed-upstream https://mail.python.org/pipermail/pyopenssl-users/2013-September/000478.html In all prior releases, the string formatting of subjectAltName X509Extension instances incorrectly truncated fields of the

Bug#722055: python-openssl: CVE-2013-4314: hostname check bypassing vulnerability

2013-09-07 Thread Salvatore Bonaccorso
Hi The reference to upstream diff: http://bazaar.launchpad.net/~exarkun/pyopenssl/trunk/revision/169 Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org