Open
Description
Details | |
---|---|
Package | openssl |
Version | 0.10.44 |
URL | sfackler/rust-openssl#1854 |
Patched Versions | >=0.10.48 |
Aliases | GHSA-9qwg-crg9-m2vc |
SubjectAlternativeName
and ExtendedKeyUsage
arguments were parsed using the OpenSSL
function X509V3_EXT_nconf
. This function parses all input using an OpenSSL mini-language
which can perform arbitrary file reads.
Thanks to David Benjamin (Google) for reporting this issue.
Metadata
Metadata
Assignees
Labels
No labels