Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 184934 - net-misc/curl < 7.16.4 certificate time validation weakness (CVE-2007-3564)
Summary: net-misc/curl < 7.16.4 certificate time validation weakness (CVE-2007-3564)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://curl.haxx.se/docs/adv_20070710...
Whiteboard: B4 [noglsa]
Keywords:
: 186215 (view as bug list)
Depends on:
Blocks:
 
Reported: 2007-07-11 09:09 UTC by Daniel Black (RETIRED)
Modified: 2007-08-25 22:11 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Daniel Black (RETIRED) gentoo-dev 2007-07-11 09:09:33 UTC
certificate time is not validated with GNUTLS SSL library enabled (USE=gnutls)

curl-7.16.4 fixes this problem. Please revdep-rebuild when updating.
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2007-07-11 10:52:44 UTC
Please, hold your horses for a bit, thanks. This would be better backported to a version that doesn't break ABI, dragonheart is working on it. :)
Comment 2 Daniel Black (RETIRED) gentoo-dev 2007-07-12 08:54:38 UTC
choice of stable version is available 7.16.4 or backported 7.15.5-r1

If 7.16.4 is selected as the stable ebuild then the following would need to be stabilized so they can compile correctly:
ocurl-0.2.1 (prev stable dev-ml/ocurl-0.1.6)
authforce-0.9.9 (prev stable net-analyzer/authforce-0.9.6)
icecast-2.3.1-r1 (prev stable icecast-2.2.0 amd64 ppc64 sparc x86, icecast-2.1.0 alpha & ppc)
pycurl-7.16.2.1 (prev stable pycurl-7.15.1)

curl-7.15.5-r1 added if an ABI bump isn't desired. Curl has a rather large list of ABI breaks. Significant bug fixes have occurred since 7.15.5 though http://curl.haxx.se/changes.html.

ref B2. Thinking this is too high. Only the validation time interval isn't checked. CN, certificate chain are checked. To exploit an old valid certificate needs to be obtained + some dns spoofing and social engineering to trick the client.
Comment 3 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-07-19 08:46:04 UTC
ok so let's go for the backported version fix.
Arches, please test and mark stable curl-7.15.5-r1.
target keywords are:
curl-7.15.5-r1.ebuild:KEYWORDS="alpha amd64 arm hppa ia64 mips ppc ppc64 s390 sh sparc x86 ~x86-fbsd"
Comment 4 Jeroen Roovers (RETIRED) gentoo-dev 2007-07-19 10:34:11 UTC
Stable for HPPA.
Comment 5 Markus Rothe (RETIRED) gentoo-dev 2007-07-19 15:51:42 UTC
ppc64 stable
Comment 6 Raúl Porcel (RETIRED) gentoo-dev 2007-07-19 18:22:26 UTC
alpha/ia64/x86 stable
Comment 7 Tobias Scherbaum (RETIRED) gentoo-dev 2007-07-20 17:36:50 UTC
ppc stable
Comment 8 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-07-22 12:14:00 UTC
*** Bug 186215 has been marked as a duplicate of this bug. ***
Comment 9 Gustavo Zacarias (RETIRED) gentoo-dev 2007-07-24 15:53:42 UTC
sparc stable.
Comment 10 Mart Raudsepp gentoo-dev 2007-08-06 07:56:21 UTC
Remove mips from CC as they now have 7.16.4 stable
Comment 11 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-08-12 19:39:24 UTC
Why is this bug a B2? i would have say B4, and i would vote noglsa..
Comment 12 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-08-13 16:41:23 UTC
Agreed, voting no and closing without glsa.Feel free to reopen if you disagree.