Bug 1083303 (CVE-2014-0161) - CVE-2014-0161 ovirt-engine-sdk-python: does not verify that the remote endpoint's hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate
Summary: CVE-2014-0161 ovirt-engine-sdk-python: does not verify that the remote endpoi...
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: CVE-2014-0161
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1082595 1198753 1198754
Blocks: 1083304
TreeView+ depends on / blocked
 
Reported: 2014-04-01 21:48 UTC by Vincent Danen
Modified: 2019-09-29 13:15 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2015-03-04 18:40:18 UTC
Embargoed:


Attachments (Terms of Use)

Description Vincent Danen 2014-04-01 21:48:31 UTC
It was reported [1] that oVirt's Python SDK does not verify that the hostname of the remote endpoint matches the Common Name (CN) or subjectAltName as specified by its x.509 certificate in a TLS/SSL session.  This could allow man-in-the-middle attackers to spoof remote endpoints via an arbitrary yet valid certificate.

[1] https://bugzilla.redhat.com/show_bug.cgi?id=1082595

Comment 1 Kurt Seifried 2015-03-04 18:30:54 UTC
Created ovirt-engine-sdk-python tracking bugs for this issue:

Affects: fedora-all [bug 1198753]
Affects: epel-6 [bug 1198754]


Note You need to log in before you can comment on or make changes to this bug.