[Bug 1380038] [NEW] SSL problems: doesn't check certificate chain and hostname when ssl connecting

2014-10-11 Thread rainkin
*** This bug is a security vulnerability *** Public security bug reported: Recently, we are trying to find SSL security problems by static analysis. For example, as we all know, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or

[Bug 1380038] [NEW] SSL problems: doesn't check certificate chain and hostname when ssl connecting

2014-10-11 Thread rainkin
*** This bug is a security vulnerability *** Public security bug reported: Recently, we are trying to find SSL security problems by static analysis. For example, as we all know, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or