Bug 1165022 - vdsclient does not validate certficate hostname to vdsm
Summary: vdsclient does not validate certficate hostname to vdsm
Keywords:
Status: CLOSED DUPLICATE of bug 1165015
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1165442 1165462
Blocks: 1164675
TreeView+ depends on / blocked
 
Reported: 2014-11-18 06:56 UTC by Murray McAllister
Modified: 2019-09-29 13:23 UTC (History)
16 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-02-12 05:35:43 UTC
Embargoed:


Attachments (Terms of Use)

Description Murray McAllister 2014-11-18 06:56:12 UTC
Multiple security flaws were found in the vdsm SSL certificate validation code. Details:

Vdsclient can connect to VDSM services for remote management of virtual hosts stored on a remote node. During the connection the remote node presents a certificate.  The hostname of the remote host is presented in the certificate but not validated by the client connection to ensure that the host matches the correct name.  The SSL client should compare the hostname presented in the certificate to the host name returned in the server certificates "Common Name" field of the "subjectDN" entry. If this is not the case the connection should fail.

Comment 4 Kurt Seifried 2015-02-12 05:35:43 UTC

*** This bug has been marked as a duplicate of bug 1165015 ***


Note You need to log in before you can comment on or make changes to this bug.