[Bug 1380235] Re: Potential Vulnerability for X509 Certificate Verification

2014-12-30 Thread Launchpad Bug Tracker
[Expired for spamassassin (Ubuntu) because there has been no activity for 60 days.] ** Changed in: spamassassin (Ubuntu) Status: Incomplete => Expired -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to spamassassin in Ubuntu. https

[Bug 1380235] Re: Potential Vulnerability for X509 Certificate Verification

2014-10-31 Thread Jamie Strandboge
Thank you for reporting a bug in Ubuntu. Has this issue been files/forwarded upstream? ** Changed in: spamassassin (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to spamassassin in Ubuntu. https:

[Bug 1380235] Re: Potential Vulnerability for X509 Certificate Verification

2014-10-13 Thread Jerry Zhang
** Description changed: Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step when using SSL/TLS, which might cause severe man in the middle attack and break the entire TLS mechanism. We believe that spamc didn't check wheth