Get a Pentest and security assessment of your IT network.

Advisories

Debian Linux Security Advisory 1904-1

Debian Linux Security Advisory 1904-1 – Daniel Stenberg discovered that wget, a network utility to retrieve files from the Web using http(s) and ftp, is vulnerable to the “Null Prefix Attacks Against SSL/TLS Certificates” published at the Blackhat conference some time ago. This allows an attacker to perform undetected man-in-the-middle attacks via a crafted ITU-T X.509 certificate with an injected null byte in the Common Name field.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/81913/dsa-1904-1.txt

Source: https://packetstormsecurity.com/files/81913/Debian-Linux-Security-Advisory-1904-1.html

Related posts
Advisories

crossZone.txt

Advisories

Secunia Security Advisory 16900

Advisories

Secunia Security Advisory 19793

Advisories

Secunia Security Advisory 22534