Re: [fpc-devel] Request for review of patch for security risk in fcl-web/openssl

2023-11-05 Thread Michael Van Canneyt via fpc-devel
On Sat, 4 Nov 2023, Peter via fpc-devel wrote: Hi, Issue 40479 is about a security risk when OpenSSL is used in fcl-web (TFPHTTPClient). Using the current source/trunk, TLS certificates having a wrong hostname are accepted, while they should be rejected. An easy patch for this is available,

[fpc-devel] Request for review of patch for security risk in fcl-web/openssl

2023-11-05 Thread Peter via fpc-devel
Hi, Issue 40479 is about a security risk when OpenSSL is used in fcl-web (TFPHTTPClient). Using the current source/trunk, TLS certificates having a wrong hostname are accepted, while they should be rejected. An easy patch for this is available, I kindly ask for a review by one of the developers: