Bug 620219 (CVE-2010-3901)
Summary: | CVE-2010-3901 OpenConnect: Always validate server certificate, check server hostname against its certificate | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | dwmw2 |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2011-06-01 13:26:23 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 620220 | ||
Bug Blocks: |
Description
Jan Lieskovsky
2010-08-01 15:50:14 UTC
This issues affect the versions of the openconnect package, as shipped with Fedora release of 12 and 13. Please rebase to new version. Created openconnect tracking bugs for this issue Affects: fedora-all [bug 620220] If we're going to treat this as a security advisory rather than the eventual completion of a known-missing feature (as I suppose we probably should), then I would very much appreciate it if someone from the security team could review my cert-validation code. It sucks that I had to write this for myself, and that OpenSSL didn't provide a library function which did most of it for me. App developers are too stupid to be trusted with such things, as a rule. See the verify_peer() and match_cert_hostname() functions, and helpers, at http://git.infradead.org/users/dwmw2/openconnect.git/blob/v2.25:/ssl.c#l496 Updates processing seems to be a little slow atm. https://admin.fedoraproject.org/updates/openconnect-2.25-1.fc12 https://admin.fedoraproject.org/updates/openconnect-2.25-1.fc13 openconnect-2.25-1.fc12 has been pushed to the Fedora 12 stable repository. If problems still persist, please make note of it in this bug report. openconnect-2.25-1.fc13 has been pushed to the Fedora 13 stable repository. If problems still persist, please make note of it in this bug report. The CVE identifier of CVE-2010-3901 has been assigned to this issue. |