Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1101347 - (CVE-2014-3250) CVE-2014-3250 puppet: certificates could be honored even when revoked
CVE-2014-3250 puppet: certificates could be honored even when revoked
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20140610,repor...
: Security
Depends On: 1107897 1108503
Blocks: 1101348
  Show dependency treegraph
 
Reported: 2014-05-26 23:06 EDT by Murray McAllister
Modified: 2018-06-29 18:01 EDT (History)
28 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
upstream patch (9.35 KB, patch)
2014-05-26 23:09 EDT, Murray McAllister
no flags Details | Diff
revised upstream patch (9.35 KB, patch)
2014-06-05 01:08 EDT, Murray McAllister
no flags Details | Diff

  None (edit)
Description Murray McAllister 2014-05-26 23:06:40 EDT
Upstream reports:

""
In Apache 2.4, SSLCARevocationCheck directive was added to mod_ssl,
which defaults it to none and must be explicitly configured. This
setting enables checking of a certificate revocation list. The default
Puppet master vhost config shipped with Puppet does not include this
setting. If a Puppet master is set up to run with Apache 2.4, and this
default vhost configuration file is used, the Puppet master will
continue to honor a host's certificate even after it is revoked.
""

Acknowledgements:

Red Hat would like to thank Puppet Labs for reporting this issue.
Comment 2 Murray McAllister 2014-05-26 23:09:26 EDT
Created attachment 899367 [details]
upstream patch
Comment 6 Murray McAllister 2014-06-05 01:08:27 EDT
Created attachment 902402 [details]
revised upstream patch
Comment 8 Murray McAllister 2014-06-10 21:13:01 EDT
(In reply to Murray McAllister from comment #6)
> Created attachment 902402 [details]
> revised upstream patch

A revision was not needed here. It is OK for it to be identical to the obsoleted patch.
Comment 9 Murray McAllister 2014-06-10 21:15:55 EDT
This issue was fixed in upstream version Puppet 3.6.2.

External References:

http://puppetlabs.com/security/cve/CVE-2014-3250
Comment 10 Murray McAllister 2014-06-10 21:16:49 EDT
Created puppet tracking bugs for this issue:

Affects: fedora-all [bug 1107897]
Comment 11 Kurt Seifried 2014-06-12 03:07:59 EDT
Statement:

Not vulnerable. This issue did not affect the versions of puppet as shipped with Red Hat Subscription Asset Manager 1.3 as they did not include puppet-server.

Note You need to log in before you can comment on or make changes to this bug.