USN-8902-1: libarchive vulnerability
USN-8902-1
It was discovered that libgit2 incorrectly handled IP address SubjectAltName verification in TLS certificate validation. A remote attacker with a CA-trusted certificate could possibly use this issue to perform a machine-in-the-middle attack, leading to the exposure of sensitive information.
A separate affected-products list was not included in the collected bulletin.
Separate remediation guidance was not included in the collected bulletin.
No CVE identifiers were listed in the collected bulletin.
The publication date reported by the vendor.
We collected the advisory from the official source.