Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 471094 (CVE-2013-2073) - <app-i18n/transifex-client-0.9.2 : Certificate Verification Security Issue (CVE-2013-2073)
Summary: <app-i18n/transifex-client-0.9.2 : Certificate Verification Security Issue (C...
Status: RESOLVED FIXED
Alias: CVE-2013-2073
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/53413/
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-05-23 17:09 UTC by Agostino Sarubbo
Modified: 2014-01-29 11:30 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-05-23 17:09:34 UTC
From ${URL} :

Description
A security issue has been reported in transifex-client, which can be exploited by malicious people 
to conduct spoofing attacks.

The security issue is caused due to the application not properly verifying the server SSL 
certificate. This can be exploited to e.g. spoof the server via a MitM (Man-in-the-Middle) attack 
and e.g. disclose potentially sensitive information.

The security issue is reported in version 0.8. Prior versions may also be affected.


Solution
Update to version 0.9.

Provided and/or discovered by
Florian Weimer, Red Hat Product Security Team.

Original Advisory
Transifex:
http://blog.transifex.com/post/51072109836/new-version-of-the-transifex-client-has-been-released


@maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not.
Comment 1 Markos Chandras (RETIRED) gentoo-dev 2013-05-23 17:16:29 UTC
The package is already in tree. Go ahead and stabilize it
Comment 2 Markos Chandras (RETIRED) gentoo-dev 2013-06-29 23:16:20 UTC
Please CC the arches whenever you feel ready
Comment 3 Chris Reffett (RETIRED) gentoo-dev Security 2013-06-30 12:26:08 UTC
I don't see any reason not to. Arches, please stable =app-i18n/transifex-client-0.9.2, target arches amd64, x86. Thanks!
Comment 4 Agostino Sarubbo gentoo-dev 2013-06-30 16:58:39 UTC
amd64 stable
Comment 5 Agostino Sarubbo gentoo-dev 2013-06-30 17:14:01 UTC
x86 stable
Comment 6 Sergey Popov gentoo-dev 2013-08-24 05:46:04 UTC
GLSA vote: no
Comment 7 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2014-01-29 11:30:41 UTC
GLSA vote: no.

Closing as [noglsa]