Permalink
Browse files

MDL-40615 Repository: Updated Amazon S3 library

Fixed insecure use of CURLOPT_SSL_VERIFYHOST
  • Loading branch information...
1 parent 863d00c commit c5cb333a383b670852dad7ab7d334438d10e2d43 @FMCorz FMCorz committed with Sam Hemelryk Jul 19, 2013
Showing with 2 additions and 3 deletions.
  1. +1 −2 repository/s3/README_MOODLE.txt
  2. +1 −1 repository/s3/S3.php
@@ -3,8 +3,7 @@
Amazon S3 PHP Class
Cloned from git://github.com/tpyo/amazon-s3-php-class.git
-Branch master
-On July 23rd 2012
+At commit 56770370c33a5310c5e07a9d22aef8c162f150ee
https://github.com/tpyo/amazon-s3-php-class
http://undesigned.org.za/2007/10/22/amazon-s3-php-class
View
@@ -1809,7 +1809,7 @@ public function getResponse()
if (S3::$useSSL)
{
// SSL Validation can now be optional for those with broken OpenSSL installations
- curl_setopt($curl, CURLOPT_SSL_VERIFYHOST, S3::$useSSLValidation ? 1 : 0);
+ curl_setopt($curl, CURLOPT_SSL_VERIFYHOST, S3::$useSSLValidation ? 2 : 0);
curl_setopt($curl, CURLOPT_SSL_VERIFYPEER, S3::$useSSLValidation ? 1 : 0);
if (S3::$sslKey !== null) curl_setopt($curl, CURLOPT_SSLKEY, S3::$sslKey);

0 comments on commit c5cb333

Please sign in to comment.