Files
advisory-db/crates/security-framework/RUSTSEC-2017-0003.toml
Sergey "Shnatsel" Davidoff 7797133c67 Add CVE mapping
2020-03-18 17:15:13 +01:00

20 lines
591 B
TOML

[advisory]
id = "RUSTSEC-2017-0003"
package = "security-framework"
date = "2017-03-15"
keywords = ["mitm"]
url = "https://github.com/sfackler/rust-security-framework/pull/27"
title = "Hostname verification skipped when custom root certs used"
description = """
If custom root certificates were registered with a `ClientBuilder`, the
hostname of the target server would not be validated against its presented leaf
certificate.
This issue was fixed by properly configuring the trust evaluation logic to
perform that check.
"""
aliases = ["CVE-2017-18588"]
[versions]
patched = [">= 0.1.12"]