UbuntuUpdates.org

Package "libserf1"

Name: libserf1

Description:

high-performance asynchronous HTTP client library

Latest version: 1.0.0-2ubuntu0.1
Release: precise (12.04)
Level: security
Repository: main
Head package: serf
Homepage: http://code.google.com/p/serf/

Links


Download "libserf1"


Other versions of "libserf1" in Precise

Repository Area Version
base main 1.0.0-2
updates main 1.0.0-2ubuntu0.1

Changelog

Version: 1.0.0-2ubuntu0.1 2014-08-14 18:06:32 UTC

  serf (1.0.0-2ubuntu0.1) precise-security; urgency=medium

  * SECURITY UPDATE: cert spoofing via NUL characters in CommonName and
    SubjectAltNames
    - debian/patches/CVE-2014-3504.patch: escape null bytes in
      buckets/ssl_buckets.c.
    - CVE-2014-3504
 -- Marc Deslauriers <email address hidden> Thu, 14 Aug 2014 10:51:37 -0400

CVE-2014-3504 failure to properly handle a NUL character in the CommonName or SubjectAltNames fields



About   -   Send Feedback to @ubuntu_updates