This is an old revision of the document!


Slackware-10.2 ChangeLog (2009-08-14)

Fri Aug 14 13:42:26 CDT 2009

patches/packages/curl-7.12.2-i486-4_slack10.2.tgz:
This update fixes a security issue where a zero byte embedded in an SSL
or TLS certificate could fool cURL into validating the security of a
connection to a system that the certificate was not issued for. It has
been reported that at least one Certificate Authority allowed such
certificates to be issued.
For more information, see:
http://curl.haxx.se/docs/security.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2417
(* Security fix *)
  • news/2009/08/14/slackware-10.2-changelog.1486075365.txt.gz
  • Last modified: 7 years ago
  • by Giuseppe Di Terlizzi