Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The X509Extension in pyOpenSSL before 0.13.1 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
pyOpenSSL SSL客户端证书验证安全绕过漏洞
Vulnerability Description
Python是Python软件基金会的一套开源的、面向对象的程序设计语言。pyOpenSSL是其中的一个OpenSSL接口。 pyOpenSSL 0.13之前版本中的X509Extension类中存在漏洞,该漏洞源于程序没有正确地处理X.509证书的Subject Alternative Name字段中域名中的‘’字符。中间人攻击者可借助由合法证书颁发机构所发布的特制证书,利用该漏洞欺骗任意SSL服务器。
CVSS Information
N/A
Vulnerability Type
N/A