Control: retitle -1 tweepy: CVE-2012-5825 Fail to verify hostname against X.509 
certificate

I looked into how to get a fix for this issue into Debian stable (Jessie).
It is easier said than done, as the fix implemented upstream was to rewrite
the HTTPS connection code from using httplib to using eequests, ie a different
python library.  I doubt such change would be accepted by the
release managers, and do not intend to spend more time on it.  Sad to say,
but I believe this security issue will have to stay around in Debian Stable.

See also
<URL: https://security-tracker.debian.org/tracker/CVE-2012-5825 >.

-- 
Happy hacking
Petter Reinholdtsen

_______________________________________________
Python-modules-team mailing list
Python-modules-team@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/python-modules-team

Reply via email to