Hacker News new | ask | show | jobs
by richm44 352 days ago
Time for me to dust off CVE-2010-3170 again? :-)
1 comments

I guess a bunch of "roll your own X.509 validation"-logic will have that bug, but to exploit it you need a misbehaving CA to issue you such a cert (i.e. low likelihood)