Bug 1374266 (CVE-2016-7444)

Summary: CVE-2016-7444 gnutls: Incorrect certificate validation when using OCSP responses (GNUTLS-SA-2016-3)
Product: [Other] Security Response Reporter: Adam Mariš <amaris>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: anemec, erik-fedora, mike, nmavrogi, rjones, sardella, slawomir, tmraz
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: gnutls 3.4.15, gnutls 3.5.4 Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the way GnuTLS validated certificates using OCSP responses. This could falsely report a certificate as valid under certain circumstances.
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-09-13 06:45:03 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1374267, 1374269, 1374270, 1377569    
Bug Blocks: 1374271, 1415638    

Description Adam Mariš 2016-09-08 11:25:34 UTC
It was found an issue in certificate validation using OCSP responses caused by not verifying the serial length, which can falsely report a certificate as valid.

Upstream patch:

https://gitlab.com/gnutls/gnutls/commit/964632f37dfdfb914ebc5e49db4fa29af35b1de9

External References:

https://www.gnutls.org/security.html
https://lists.gnupg.org/pipermail/gnutls-devel/2016-September/008146.html

Comment 1 Adam Mariš 2016-09-08 11:28:06 UTC
Created mingw-gnutls tracking bugs for this issue:

Affects: fedora-all [bug 1374269]
Affects: epel-7 [bug 1374270]

Comment 2 Adam Mariš 2016-09-08 11:28:12 UTC
Created gnutls tracking bugs for this issue:

Affects: fedora-all [bug 1374267]

Comment 5 Fedora Update System 2016-09-12 13:18:14 UTC
gnutls-3.5.4-1.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2016-09-13 22:23:50 UTC
gnutls-3.4.15-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.

Comment 7 Fedora Update System 2016-09-14 01:19:14 UTC
gnutls-3.4.15-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.

Comment 8 Fedora Update System 2016-09-14 15:55:01 UTC
mingw-gnutls-3.5.4-1.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.

Comment 9 Andrej Nemec 2016-09-19 09:33:32 UTC
CVE assignment:

http://seclists.org/oss-sec/2016/q3/549

Comment 12 errata-xmlrpc 2017-08-01 08:49:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2017:2292 https://access.redhat.com/errata/RHSA-2017:2292