Le mercredi 13 mars 2013 à 11:58 -0600, Vincent Danen a écrit :
> This issue was given the name CVE-2010-3312 quite a while ago.  See
> https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3312 for more info.

I don’t think this is the same issue. The problem reported here is
specifically about redirections, while CVE-2010-3312 (#564690 in Debian)
was about *never* verifying SSL certs (and is now fixed).

-- 
 .''`.    Sébastien Villemot
: :' :    Debian Developer
`. `'     http://www.dynare.org/sebastien
  `-      GPG Key: 4096R/381A7594

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to