←back to thread

320 points Bogdanp | 2 comments | | HN request time: 0.401s | source
1. richm44 ◴[] No.44379904[source]
Time for me to dust off CVE-2010-3170 again? :-)
replies(1): >>44381602 #
2. NicolaiS ◴[] No.44381602[source]
I guess a bunch of "roll your own X.509 validation"-logic will have that bug, but to exploit it you need a misbehaving CA to issue you such a cert (i.e. low likelihood)