Debian Linux Security Advisory 1904-1 – Daniel Stenberg discovered that wget, a network utility to retrieve files from the Web using http(s) and ftp, is vulnerable to the “Null Prefix Attacks Against SSL/TLS Certificates” published at the Blackhat conference some time ago. This allows an attacker to perform undetected man-in-the-middle attacks via a crafted ITU-T X.509 certificate with an injected null byte in the Common Name field.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/81913/dsa-1904-1.txt
Source: https://packetstormsecurity.com/files/81913/Debian-Linux-Security-Advisory-1904-1.html

