Bug 894352 (CVE-2013-0240, CVE-2013-1799) - CVE-2013-0240 gnome-online-accounts: Does not check SSL certificates when creating Windows Live or Facebook accounts
Summary: CVE-2013-0240 gnome-online-accounts: Does not check SSL certificates when cre...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2013-0240, CVE-2013-1799
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 908000
Blocks: 895069
TreeView+ depends on / blocked
 
Reported: 2013-01-11 14:17 UTC by Simon McVittie
Modified: 2023-05-12 22:14 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2013-04-18 20:31:36 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
GNOME Bugzilla 693214 0 None None None Never

Comment 2 Jan Lieskovsky 2013-01-14 13:16:09 UTC
This issue affects the versions of the gnome-online-accounts package, as shipped with Fedora release of 16 and 17.

Comment 6 Jan Lieskovsky 2013-02-05 15:51:01 UTC
It was found that Gnome Online Accounts (GOA) did not perform SSL certificate validation, when performing Windows Live and Facebook accounts creation. A remote attacker could use this flaw to conduct man-in-the-middle (MiTM) attacks, possibly leading to their ability to obtain sensitive information.

Comment 7 Jan Lieskovsky 2013-02-05 15:53:06 UTC
Acknowledgements:

Red Hat would like to thank Simon McVittie for reporting this issue.

Comment 9 Jan Lieskovsky 2013-02-05 16:06:14 UTC
Created gnome-online-accounts tracking bugs for this issue

Affects: fedora-all [bug 908000]

Comment 13 Fedora Update System 2013-02-27 02:41:22 UTC
gnome-online-accounts-3.4.2-3.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 14 Fedora Update System 2013-03-19 20:00:45 UTC
gnome-online-accounts-3.6.3-1.fc18 has been pushed to the Fedora 18 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 15 Vincent Danen 2013-03-28 18:04:17 UTC
Just to note that CVE-2013-1799 was assigned to the incomplete fix present in 3.6.3 and 3.7.5 (I'm presuming some beta or pre-releases).


Common Vulnerabilities and Exposures assigned an identifier CVE-2013-0240 to
the following vulnerability:

Name: CVE-2013-0240
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0240
Assigned: 20121206
Reference: https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00007.html
Reference: https://bugzilla.redhat.com/show_bug.cgi?id=894352
Reference: https://bugzilla.gnome.org/show_bug.cgi?id=693214
Reference: https://git.gnome.org/browse/gnome-online-accounts/commit/?h=gnome-3-6&id=ecad8142e9ac519b9fc74b96dcb5531052bbffe1
Reference: https://git.gnome.org/browse/gnome-online-accounts/commit/?id=bc10fdb68f75f8be84eb698ada08743b9c7c248f
Reference: https://git.gnome.org/browse/gnome-online-accounts/commit/?id=edde7c63326242a60a075341d3fea0be0bc4d80e

Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x
before 3.7.5, does not properly validate SSL certificates when
creating accounts such as Windows Live and Facebook accounts, which
allows man-in-the-middle attackers to obtain sensitive information
such as credentials by sniffing the network.


Common Vulnerabilities and Exposures assigned an identifier CVE-2013-1799 to
the following vulnerability:

Name: CVE-2013-1799
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1799
Assigned: 20130219
Reference: https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00007.html
Reference: https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00020.html
Reference: https://bugzilla.gnome.org/show_bug.cgi?id=693214
Reference: https://bugzilla.gnome.org/show_bug.cgi?id=695106
Reference: https://git.gnome.org/browse/gnome-online-accounts/commit/?id=9cf4bc0ced2c53bcdd36922caa65afc8a167bbd8


Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before
3.7.91, does not properly validate SSL certificates when creating
accounts for providers who use the libsoup library, which allows
man-in-the-middle attackers to obtain sensitive information such as
credentials by sniffing the network.  NOTE: this issue exists because
of an incomplete fix for CVE-2013-0240.

I do not believe that CVE-2013-1799 affects us as we have the fixed 3.6.3 and 3.4.2 updates.  Can someone confirm that this is indeed the case?


Note You need to log in before you can comment on or make changes to this bug.