QSslSocket: fix security vulnerability with wildcard IP addresses
authorPeter Hartmann <peter.hartmann@nokia.com>
Tue, 10 Aug 2010 11:59:57 +0000 (13:59 +0200)
committerPeter Hartmann <peter.hartmann@nokia.com>
Tue, 10 Aug 2010 12:31:43 +0000 (14:31 +0200)
commit87c62128266a4e2289c1854e35aba3fc17d44045
tree3936623d671e741d95c4dcb33e7ce0ee2f9f8a74
parentb5f95fbf615b113e3e6d2b42f6b84309d6588b1f
QSslSocket: fix security vulnerability with wildcard IP addresses

This fixes Westpoint Security issue with Advisory ID#: wp-10-0001.
Before, we would allow wildcards in IP addresses like *.2.3.4 ; now,
IP addresses must match excatly.

Patch-by: Richard J. Moore <rich@kde.org>
Task-number: QT-3704
src/network/ssl/qsslsocket_openssl.cpp
tests/auto/qsslsocket/tst_qsslsocket.cpp