Bug 894352 (CVE-2013-0240, CVE-2013-1799)

Summary: CVE-2013-0240 gnome-online-accounts: Does not check SSL certificates when creating Windows Live or Facebook accounts
Product: [Other] Security Response Reporter: Simon McVittie <simon.mcvittie>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: debarshir, jlieskov, jrusnack, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-04-18 20:31:36 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 908000    
Bug Blocks: 895069    

Comment 2 Jan Lieskovsky 2013-01-14 13:16:09 UTC
This issue affects the versions of the gnome-online-accounts package, as shipped with Fedora release of 16 and 17.

Comment 6 Jan Lieskovsky 2013-02-05 15:51:01 UTC
It was found that Gnome Online Accounts (GOA) did not perform SSL certificate validation, when performing Windows Live and Facebook accounts creation. A remote attacker could use this flaw to conduct man-in-the-middle (MiTM) attacks, possibly leading to their ability to obtain sensitive information.

Comment 7 Jan Lieskovsky 2013-02-05 15:53:06 UTC
Acknowledgements:

Red Hat would like to thank Simon McVittie for reporting this issue.

Comment 9 Jan Lieskovsky 2013-02-05 16:06:14 UTC
Created gnome-online-accounts tracking bugs for this issue

Affects: fedora-all [bug 908000]

Comment 13 Fedora Update System 2013-02-27 02:41:22 UTC
gnome-online-accounts-3.4.2-3.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 14 Fedora Update System 2013-03-19 20:00:45 UTC
gnome-online-accounts-3.6.3-1.fc18 has been pushed to the Fedora 18 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 15 Vincent Danen 2013-03-28 18:04:17 UTC
Just to note that CVE-2013-1799 was assigned to the incomplete fix present in 3.6.3 and 3.7.5 (I'm presuming some beta or pre-releases).


Common Vulnerabilities and Exposures assigned an identifier CVE-2013-0240 to
the following vulnerability:

Name: CVE-2013-0240
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0240
Assigned: 20121206
Reference: https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00007.html
Reference: https://bugzilla.redhat.com/show_bug.cgi?id=894352
Reference: https://bugzilla.gnome.org/show_bug.cgi?id=693214
Reference: https://git.gnome.org/browse/gnome-online-accounts/commit/?h=gnome-3-6&id=ecad8142e9ac519b9fc74b96dcb5531052bbffe1
Reference: https://git.gnome.org/browse/gnome-online-accounts/commit/?id=bc10fdb68f75f8be84eb698ada08743b9c7c248f
Reference: https://git.gnome.org/browse/gnome-online-accounts/commit/?id=edde7c63326242a60a075341d3fea0be0bc4d80e

Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x
before 3.7.5, does not properly validate SSL certificates when
creating accounts such as Windows Live and Facebook accounts, which
allows man-in-the-middle attackers to obtain sensitive information
such as credentials by sniffing the network.


Common Vulnerabilities and Exposures assigned an identifier CVE-2013-1799 to
the following vulnerability:

Name: CVE-2013-1799
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1799
Assigned: 20130219
Reference: https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00007.html
Reference: https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00020.html
Reference: https://bugzilla.gnome.org/show_bug.cgi?id=693214
Reference: https://bugzilla.gnome.org/show_bug.cgi?id=695106
Reference: https://git.gnome.org/browse/gnome-online-accounts/commit/?id=9cf4bc0ced2c53bcdd36922caa65afc8a167bbd8


Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before
3.7.91, does not properly validate SSL certificates when creating
accounts for providers who use the libsoup library, which allows
man-in-the-middle attackers to obtain sensitive information such as
credentials by sniffing the network.  NOTE: this issue exists because
of an incomplete fix for CVE-2013-0240.

I do not believe that CVE-2013-1799 affects us as we have the fixed 3.6.3 and 3.4.2 updates.  Can someone confirm that this is indeed the case?