diff --git a/docs/CVE-2024-7264.md b/docs/CVE-2024-7264.md index bd2c816fd6..4c5ab2f8ae 100644 --- a/docs/CVE-2024-7264.md +++ b/docs/CVE-2024-7264.md @@ -20,7 +20,7 @@ getting returned to the application when INFO ---- -The ANS.1 parsing is done *after* a successful TLS handshake, which then also +The ASN.1 parsing is done *after* a successful TLS handshake, which then also means that the used TLS library has parsed the certificate. If the TLS library rejects the bad date string, then it cannot reach and trigger libcurl's bug. We can however not be sure that there are not circumstances in which the bad