Bug 1374266 (CVE-2016-7444) - CVE-2016-7444 gnutls: Incorrect certificate validation when using OCSP responses (GNUTLS-SA-2016-3)
Summary: CVE-2016-7444 gnutls: Incorrect certificate validation when using OCSP respon...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2016-7444
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1374267 1374269 1374270 1377569
Blocks: 1374271 1415638
TreeView+ depends on / blocked
 
Reported: 2016-09-08 11:25 UTC by Adam Mariš
Modified: 2021-02-17 03:22 UTC (History)
8 users (show)

Fixed In Version: gnutls 3.4.15, gnutls 3.5.4
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the way GnuTLS validated certificates using OCSP responses. This could falsely report a certificate as valid under certain circumstances.
Clone Of:
Environment:
Last Closed: 2018-09-13 06:45:03 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2017:2292 0 normal SHIPPED_LIVE Moderate: gnutls security, bug fix, and enhancement update 2017-08-01 12:39:15 UTC

Description Adam Mariš 2016-09-08 11:25:34 UTC
It was found an issue in certificate validation using OCSP responses caused by not verifying the serial length, which can falsely report a certificate as valid.

Upstream patch:

https://gitlab.com/gnutls/gnutls/commit/964632f37dfdfb914ebc5e49db4fa29af35b1de9

External References:

https://www.gnutls.org/security.html
https://lists.gnupg.org/pipermail/gnutls-devel/2016-September/008146.html

Comment 1 Adam Mariš 2016-09-08 11:28:06 UTC
Created mingw-gnutls tracking bugs for this issue:

Affects: fedora-all [bug 1374269]
Affects: epel-7 [bug 1374270]

Comment 2 Adam Mariš 2016-09-08 11:28:12 UTC
Created gnutls tracking bugs for this issue:

Affects: fedora-all [bug 1374267]

Comment 5 Fedora Update System 2016-09-12 13:18:14 UTC
gnutls-3.5.4-1.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2016-09-13 22:23:50 UTC
gnutls-3.4.15-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.

Comment 7 Fedora Update System 2016-09-14 01:19:14 UTC
gnutls-3.4.15-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.

Comment 8 Fedora Update System 2016-09-14 15:55:01 UTC
mingw-gnutls-3.5.4-1.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.

Comment 9 Andrej Nemec 2016-09-19 09:33:32 UTC
CVE assignment:

http://seclists.org/oss-sec/2016/q3/549

Comment 12 errata-xmlrpc 2017-08-01 08:49:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2017:2292 https://access.redhat.com/errata/RHSA-2017:2292


Note You need to log in before you can comment on or make changes to this bug.