Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 281950 (CVE-2009-2473) - <net-libs/neon-0.28.6: Multiple vulnerabilities (CVE-2009-{2473,2474})
Summary: <net-libs/neon-0.28.6: Multiple vulnerabilities (CVE-2009-{2473,2474})
Status: RESOLVED FIXED
Alias: CVE-2009-2473
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://lists.manyfish.co.uk/pipermail...
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2009-08-18 18:19 UTC by Tobias Heinlein (RETIRED)
Modified: 2014-05-31 21:45 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tobias Heinlein (RETIRED) gentoo-dev 2009-08-18 18:19:11 UTC
Changes in release 0.28.6:
* SECURITY (CVE-2009-2473): Fix "billion laughs" attack against expat;
  could allow a Denial of Service attack by a malicious server.
* SECURITY (CVE-2009-2474): Fix handling of an embedded NUL byte in
  a certificate subject name with OpenSSL; could allow an undetected
  MITM attack against an SSL server if a trusted CA issues such a cert.
Comment 1 Arfrever Frehtes Taifersar Arahesis (RETIRED) gentoo-dev 2009-08-19 00:15:41 UTC
net-misc/neon-0.28.6 is now in the tree.
Additional informations:
http://lists.manyfish.co.uk/pipermail/neon/2009-August/001045.html
http://lists.manyfish.co.uk/pipermail/neon/2009-August/001046.html
Comment 2 Arfrever Frehtes Taifersar Arahesis (RETIRED) gentoo-dev 2009-08-19 00:20:01 UTC
Please stabilize net-misc/neon-0.28.6.
Comment 3 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-08-19 17:37:23 UTC
Sorry Arches, we need a newer GnuTLS as well. You'll be readded when it is ready.

From Redhat's bugzie/Joe Orton:
"If neon is linked against GnuTLS, version 2.8.2 or later must be used to 
avoid the vulnerability."

Arfrever, please raise the dependency. Currently there is ">=net-libs/gnutls-2.0".
Comment 5 Christian Faulhammer (RETIRED) gentoo-dev 2009-08-19 22:26:09 UTC
x86 stable
Comment 6 Jeroen Roovers (RETIRED) gentoo-dev 2009-08-20 12:47:32 UTC
Stable for HPPA.
Comment 7 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-08-21 19:49:41 UTC
CVE-2009-2473 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2473):
  neon before 0.28.6, when expat is used, does not properly detect
  recursion during entity expansion, which allows context-dependent
  attackers to cause a denial of service (memory and CPU consumption)
  via a crafted XML document containing a large number of nested entity
  references, a similar issue to CVE-2003-1564.

CVE-2009-2474 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2474):
  neon before 0.28.6, when OpenSSL is used, does not properly handle a
  '\0' character in a domain name in the subject's Common Name (CN)
  field of an X.509 certificate, which allows man-in-the-middle
  attackers to spoof arbitrary SSL servers via a crafted certificate
  issued by a legitimate Certification Authority, a related issue to
  CVE-2009-2408.

Comment 8 nixnut (RETIRED) gentoo-dev 2009-08-23 08:33:09 UTC
ppc stable
Comment 9 Brent Baude (RETIRED) gentoo-dev 2009-08-24 14:56:50 UTC
ppc64 done
Comment 10 Raúl Porcel (RETIRED) gentoo-dev 2009-08-25 13:38:49 UTC
alpha/arm/ia64/s390/sh/sparc stable
Comment 11 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-08-27 00:10:32 UTC
amd64 stable.
Arfrever, please remove the old, vulnerable versions.
GLSA voting: YES.
Comment 12 Petteri Räty (RETIRED) gentoo-dev 2009-08-28 21:25:54 UTC
(In reply to comment #11)
> amd64 stable.
> Arfrever, please remove the old, vulnerable versions.
> GLSA voting: YES.
> 

I nuked the old versions while doing built_with_use cleanup.
Comment 13 Stefan Behte (RETIRED) gentoo-dev Security 2009-09-14 21:52:36 UTC
Yes, too. Request filed.
Comment 14 Arfrever Frehtes Taifersar Arahesis (RETIRED) gentoo-dev 2011-06-07 18:22:44 UTC
How will a GLSA help users 2 years or more after fixing of the bug in the tree?
Comment 15 Alex Legler (RETIRED) archtester gentoo-dev Security 2011-06-07 19:24:09 UTC
spare me your attitude
Comment 16 Sean Amoss (RETIRED) gentoo-dev Security 2014-05-31 21:45:38 UTC
This issue has been fixed since Aug 26, 2009. No GLSA will be issued.