[issue18709] SSL module fails to handle NULL bytes inside subjectAltNames general names (CVE-2013-4073)

STINNER Victor report at bugs.python.org
Mon Aug 12 15:02:36 CEST 2013


STINNER Victor added the comment:

Does it really make sense to allow to open a certificate containing a NUL byte in its name? How does OpenSSL and other projects handle this case?

----------
nosy: +haypo

_______________________________________
Python tracker <report at bugs.python.org>
<http://bugs.python.org/issue18709>
_______________________________________


More information about the Python-bugs-list mailing list