diff options
| author | Victor Stinner <vstinner@redhat.com> | 2019-02-16 08:23:52 +0100 |
|---|---|---|
| committer | Ned Deily <nad@python.org> | 2019-02-16 02:23:52 -0500 |
| commit | 2a3af94b7e4d7851986043348128e312ddbb2451 (patch) | |
| tree | a2eaf731821c2eb6dd7d4b3001dee06cdf017380 /Misc | |
| parent | c41523ac2447b0e86b702f58458f3b3548439c8b (diff) | |
| download | cpython-git-2a3af94b7e4d7851986043348128e312ddbb2451.tar.gz | |
bpo-35746: Credit Colin Read and Nicolas Edet (GH-11865)
Add credit for the cert parser vulnerability. Mention also Cisco
TALOS-2018-0758 identifier.
Diffstat (limited to 'Misc')
| -rw-r--r-- | Misc/NEWS.d/next/Security/2019-01-15-18-16-05.bpo-35746.nMSd0j.rst | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/Misc/NEWS.d/next/Security/2019-01-15-18-16-05.bpo-35746.nMSd0j.rst b/Misc/NEWS.d/next/Security/2019-01-15-18-16-05.bpo-35746.nMSd0j.rst index dffe347eec..fc703b9c24 100644 --- a/Misc/NEWS.d/next/Security/2019-01-15-18-16-05.bpo-35746.nMSd0j.rst +++ b/Misc/NEWS.d/next/Security/2019-01-15-18-16-05.bpo-35746.nMSd0j.rst @@ -1,3 +1,4 @@ [CVE-2019-5010] Fix a NULL pointer deref in ssl module. The cert parser did not handle CRL distribution points with empty DP or URI correctly. A -malicious or buggy certificate can result into segfault. +malicious or buggy certificate can result into segfault. Vulnerability +(TALOS-2018-0758) reported by Colin Read and Nicolas Edet of Cisco. |
