Bug 1527048 (CVE-2017-17718)

Summary: CVE-2017-17718 rubygem-net-ldap: Missing SSL Certificate Validation
Product: [Other] Security Response Reporter: Adam Mariš <amaris>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: bcourt, bkabrda, bkearney, cbillett, codehotter, jmatthew, kseifried, mmccune, mrike, ohadlevy, rchan, sisharma, steve.traylen, tjay, tomckay, tsanders, vondruch
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: rubygem-net-ldap 0.16.0 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-12-19 03:39:17 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1527123, 1527124, 1527125, 1527126, 1527127, 1829551    
Bug Blocks: 1527049    

Description Adam Mariš 2017-12-18 12:38:02 UTC
The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation.

References:

https://github.com/ruby-ldap/ruby-net-ldap/issues/258
https://github.com/ruby-ldap/ruby-net-ldap/pull/279
http://openwall.com/lists/oss-security/2017/12/17/10

Comment 2 Kurt Seifried 2017-12-18 16:13:40 UTC
Statement: 

This issue affects the versions of rubygem-net-ldap as shipped with Red Hat Subscription Asset Manager 1 and Satellite version 6. Red Hat Product Security has rated this issue as having Moderate security impact. No update is planned at this time however a future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Comment 4 Cedric Buissart 2020-04-30 11:11:47 UTC
Satellite 6.7 fixed this issue via the rebase to tfm-rubygem-net-ldap-0.16.1