Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Implemented
-
3.1 (end of life)
-
None
-
None
-
All
Description
See.
http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf
Using JSSE you must manually validate server name you're connecting to matches one of the names provided by the certificate. So you can detect a man-in-the-middle type attack with a valid certificado for other site.