Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

vulnerability in database update using HTTP protocol #54

Open
fdechelle opened this issue Jun 29, 2016 · 0 comments
Open

vulnerability in database update using HTTP protocol #54

fdechelle opened this issue Jun 29, 2016 · 0 comments

Comments

@fdechelle
Copy link
Member

fdechelle commented Jun 29, 2016

vulnerability disclosed here: http://seclists.org/fulldisclosure/2016/Jun/69

index file download is done using HTTP, which allows MITM attacks. Use of HTTPS is mandatory

@fdechelle fdechelle self-assigned this Jun 29, 2016
@fdechelle fdechelle changed the title vulnerability in database update vulnerability in database update using HTTP protocol Aug 4, 2016
@fdechelle fdechelle added this to the automatic bases update milestone Aug 4, 2016
@fdechelle fdechelle removed this from the automatic bases update milestone Feb 6, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant