Mandriva: Updated Qt4 packages fix vulnerability in


 
Thread Tools Search this Thread
Special Forums Cybersecurity Security Advisories (RSS) Mandriva: Updated Qt4 packages fix vulnerability in
# 1  
Old 02-08-2008
Mandriva: Updated Qt4 packages fix vulnerability in

LinuxSecurity.com: A potential vulnerability was discovered in Qt4 version 4.3.0 through 4.3.2 which may cause a certificate verification in SSL connections not to be performed. As a result, code that uses QSslSocket could be tricked into thinking that the certificate was verified correctly when it actually failed in one or more criteria. The updated packages have been patched to correct this issue.

More...
Login or Register to Ask a Question

Previous Thread | Next Thread
Login or Register to Ask a Question
SSL_get_verify_result(3)					      OpenSSL						  SSL_get_verify_result(3)

NAME
SSL_get_verify_result - get result of peer certificate verification SYNOPSIS
#include <openssl/ssl.h> long SSL_get_verify_result(SSL *ssl); DESCRIPTION
SSL_get_verify_result() returns the result of the verification of the X509 certificate presented by the peer, if any. NOTES
SSL_get_verify_result() can only return one error code while the verification of a certificate can fail because of many reasons at the same time. Only the last verification error that occurred during the processing is available from SSL_get_verify_result(). The verification result is part of the established session and is restored when a session is reused. BUGS
If no peer certificate was presented, the returned result code is X509_V_OK. This is because no verification error occurred, it does how- ever not indicate success. SSL_get_verify_result() is only useful in connection with SSL_get_peer_certificate(3). RETURN VALUES
The following return values can currently occur: X509_V_OK The verification succeeded or no peer certificate was presented. Any other value Documented in verify(1). SEE ALSO
ssl(3), SSL_set_verify_result(3), SSL_get_peer_certificate(3), verify(1) 0.9.7a 2001-02-15 SSL_get_verify_result(3)