Bug 966269
Summary: | CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [fedora-all] | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Vincent Danen <vdanen> |
Component: | python-requests | Assignee: | Arun S A G <sagarun> |
Status: | CLOSED NOTABUG | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | 18 | CC: | a.badger, rbean, sagarun |
Target Milestone: | --- | Keywords: | Security, SecurityTracking |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Release Note | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2013-05-24 15:28:03 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 963260 |
Description
Vincent Danen
2013-05-22 22:16:55 UTC
Please use the following update submission link to create the Bodhi request for this issue as it contains the top-level parent bug(s) as well as this tracking bug. This will ensure that all associated bugs get updated when new packages are pushed to stable. Please also ensure that the "Close bugs when update is stable" option remains checked. Bodhi update submission link: https://admin.fedoraproject.org/updates/new/?type_=security&bugs=963260,966269 Vincent, python-requests no longer bundles the match_hostname code as of python-requests-1.1.0-3. See: * http://pkgs.fedoraproject.org/cgit/python-requests.git/log/h * https://admin.fedoraproject.org/updates/python-requests * https://bugzilla.redhat.com/show_bug.cgi?id=904623 The bug should be filed against python-backports-ssl_match_hostname. There is no new update to be pushed for this package. How should we proceed? Close this ticket by hand? Please advise. The bundled version of the code was removed in February 2013. https://admin.fedoraproject.org/updates/FEDORA-2013-3287/python-requests-1.1.0-3.fc17 https://admin.fedoraproject.org/updates/FEDORA-2013-3287/python-requests-1.1.0-3.fc18 http://koji.fedoraproject.org/koji/buildinfo?buildID=398972 python-backports-ssl_match_hostname update patched for this bug is currently in the testing repository: https://admin.fedoraproject.org/updates/python-backports-ssl_match_hostname Toshio did the right thing; this should be closed and the fix should be in the python-backports-ssl_match_hostname package, so while this is vulnerable now, it won't be once the other package is updated. |