Actions
Bug #8750
closedunit test fix for CVE-2013-4073 seems to be incomplete
Bug #8750:
unit test fix for CVE-2013-4073 seems to be incomplete
Description
Hello, I was just testing some Ruby versions against vulnerability against Hostname check bypassing vulnerability in SSL client (CVE-2013-4073), and it looks like the unit test added together with the fix for that issue passes even without that patch applied.
I noticed that the tampered input is using single quotes, as in
'www.example.com\0.evil.com'
I could only make those tests fail when I switched the single quotes into single quotes. This should probably apply to 1.9.3 andn 2.0.0 as well.
Files
Actions