Bug 527667 - CVE-2009-3490 wget: incorrect verification of SSL certificate with NUL in name
Summary: CVE-2009-3490 wget: incorrect verification of SSL certificate with NUL in name
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: wget
Version: 12
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Karsten Hopp
QA Contact: Fedora Extras Quality Assurance
URL: http://fedoraproject.org/wiki/Securit...
Whiteboard:
Depends On:
Blocks: CVE-2009-3490
TreeView+ depends on / blocked
 
Reported: 2009-10-07 09:29 UTC by Tomas Hoger
Modified: 2010-02-10 07:14 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2010-02-10 07:14:27 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Tomas Hoger 2009-10-07 09:29:22 UTC
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in all affected branches.

For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.

	bug #520454: CVE-2009-3490 wget: incorrect verification of SSL certificate with NUL in name

When creating a Bodhi update request, please include the bug IDs of the respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available and only close this bug once all affected Fedora versions are fixed.

Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=520454

Comment 1 Tomas Hoger 2009-10-07 09:31:17 UTC
This is to ensure we have this addressed in rawhide and hence is not missed for EL6.  F10 / F11 are affected too.

Comment 2 Bug Zapper 2009-11-16 13:21:09 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 12 development cycle.
Changing version to '12'.

More information and reason for this action is here:
http://fedoraproject.org/wiki/BugZappers/HouseKeeping

Comment 3 Vincent Danen 2009-11-16 18:45:37 UTC
This issue still affects Fedora 12, and hence RHEL6.  This needs to be resolved in Fedora 12 to ensure the fix is forward-carried to RHEL6.

Comment 4 Karsten Hopp 2009-11-17 13:34:14 UTC
wget-1.12-1.fc10, wget-1.12-1.fc11, wget-1.12-1.fc12 have been submitted to Fedora-testing


Note You need to log in before you can comment on or make changes to this bug.