[Bug 1376595] Re: X509 certificate verification problem

2014-10-11 Thread rainkin
** Information type changed from Public to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1376595 Title: X509 certificate verification problem To manage notifications about this bug

[Bug 1376595] Re: X509 certificate verification problem

2014-10-11 Thread rainkin
** Description changed: - Hostname verification is an important step when verifying X509 - certificates, however, people tend to miss the step or to misunderstand - the APIs when using SSL/TLS, which might cause severe man in the middle - attack and break the entire TLS mechanism. + Recently, we

[Bug 1376595] Re: X509 certificate verification problem

2014-10-11 Thread rainkin
** Description changed: Recently, we are trying to find SSL security problems by static anaylsis. For example, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or to misunderstand the APIs when using SSL/TLS, which might

[Bug 1376595] Re: X509 certificate verification problem

2014-10-06 Thread Steve Langasek
These are separate bugs in unrelated packages. Please do not use tasks on a single bug to track such issues. ** No longer affects: freetds (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1376595] Re: X509 certificate verification problem

2014-10-05 Thread Filip Sohajek
** Also affects: freetds (Ubuntu) Importance: Undecided Status: New ** Also affects: xfce4-mailwatch-plugin (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.