1. 18 3月, 2014 19 次提交
  2. 17 3月, 2014 20 次提交
  3. 16 3月, 2014 1 次提交
    • Travis Cross's avatar
      Mitigate the CRIME TLS flaw · 19fc943f
      Travis Cross 提交于
      If an attacker can cause a device to make an authenticated request to
      a service via TLS while including a payload of the attacker's choice
      in that request, and if TLS compression is enabled, the attacker can
      uncover the plaintext authentication information by making a series of
      guesses and observing changes in the length of the ciphertext.
      
      This is CVE-2012-4929.
      
      FS-6360 --resolve
      
      Thanks-to: Brian West <brian@freeswitch.org>
      19fc943f