Bug#805095: sflphone: Uses ALL ciphers

Kurt Roeckx kurt at roeckx.be
Sat Nov 14 17:42:19 UTC 2015


Source: sflphone
Severity: grave
Tags: security

I just saw this in the code:
        SSL_CTX_set_cipher_list(ctx, "ALL");

This enables ciphers you don't want, it might include those that
don't provide authentication or encryption.


Kurt



More information about the Pkg-voip-maintainers mailing list