Bug 894352 - (CVE-2013-0240, CVE-2013-1799) CVE-2013-0240 gnome-online-accounts: Does not check SSL certificates when creating Windows Live or Facebook accounts
CVE-2013-0240 gnome-online-accounts: Does not check SSL certificates when cre...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
Unspecified Unspecified
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20130205,repor...
: Security
Depends On: 908000
Blocks: 895069
  Show dependency treegraph
 
Reported: 2013-01-11 09:17 EST by Simon McVittie
Modified: 2015-07-31 07:02 EDT (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2013-04-18 16:31:36 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Comment 2 Jan Lieskovsky 2013-01-14 08:16:09 EST
This issue affects the versions of the gnome-online-accounts package, as shipped with Fedora release of 16 and 17.
Comment 6 Jan Lieskovsky 2013-02-05 10:51:01 EST
It was found that Gnome Online Accounts (GOA) did not perform SSL certificate validation, when performing Windows Live and Facebook accounts creation. A remote attacker could use this flaw to conduct man-in-the-middle (MiTM) attacks, possibly leading to their ability to obtain sensitive information.
Comment 7 Jan Lieskovsky 2013-02-05 10:53:06 EST
Acknowledgements:

Red Hat would like to thank Simon McVittie for reporting this issue.
Comment 9 Jan Lieskovsky 2013-02-05 11:06:14 EST
Created gnome-online-accounts tracking bugs for this issue

Affects: fedora-all [bug 908000]
Comment 13 Fedora Update System 2013-02-26 21:41:22 EST
gnome-online-accounts-3.4.2-3.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 14 Fedora Update System 2013-03-19 16:00:45 EDT
gnome-online-accounts-3.6.3-1.fc18 has been pushed to the Fedora 18 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 15 Vincent Danen 2013-03-28 14:04:17 EDT
Just to note that CVE-2013-1799 was assigned to the incomplete fix present in 3.6.3 and 3.7.5 (I'm presuming some beta or pre-releases).


Common Vulnerabilities and Exposures assigned an identifier CVE-2013-0240 to
the following vulnerability:

Name: CVE-2013-0240
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0240
Assigned: 20121206
Reference: https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00007.html
Reference: https://bugzilla.redhat.com/show_bug.cgi?id=894352
Reference: https://bugzilla.gnome.org/show_bug.cgi?id=693214
Reference: https://git.gnome.org/browse/gnome-online-accounts/commit/?h=gnome-3-6&id=ecad8142e9ac519b9fc74b96dcb5531052bbffe1
Reference: https://git.gnome.org/browse/gnome-online-accounts/commit/?id=bc10fdb68f75f8be84eb698ada08743b9c7c248f
Reference: https://git.gnome.org/browse/gnome-online-accounts/commit/?id=edde7c63326242a60a075341d3fea0be0bc4d80e

Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x
before 3.7.5, does not properly validate SSL certificates when
creating accounts such as Windows Live and Facebook accounts, which
allows man-in-the-middle attackers to obtain sensitive information
such as credentials by sniffing the network.


Common Vulnerabilities and Exposures assigned an identifier CVE-2013-1799 to
the following vulnerability:

Name: CVE-2013-1799
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1799
Assigned: 20130219
Reference: https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00007.html
Reference: https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00020.html
Reference: https://bugzilla.gnome.org/show_bug.cgi?id=693214
Reference: https://bugzilla.gnome.org/show_bug.cgi?id=695106
Reference: https://git.gnome.org/browse/gnome-online-accounts/commit/?id=9cf4bc0ced2c53bcdd36922caa65afc8a167bbd8


Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before
3.7.91, does not properly validate SSL certificates when creating
accounts for providers who use the libsoup library, which allows
man-in-the-middle attackers to obtain sensitive information such as
credentials by sniffing the network.  NOTE: this issue exists because
of an incomplete fix for CVE-2013-0240.

I do not believe that CVE-2013-1799 affects us as we have the fixed 3.6.3 and 3.4.2 updates.  Can someone confirm that this is indeed the case?

Note You need to log in before you can comment on or make changes to this bug.