Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 293158 - <dev-libs/matrixssl-3.1.3 TLS Session Renegotiation MITM vulnerability (CVE-2009-3555)
Summary: <dev-libs/matrixssl-3.1.3 TLS Session Renegotiation MITM vulnerability (CVE-2...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://www.matrixssl.org/archives/cat...
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks: CVE-2009-3555
  Show dependency tree
 
Reported: 2009-11-14 10:49 UTC by Alex Legler (RETIRED)
Modified: 2010-10-25 16:28 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alex Legler (RETIRED) archtester gentoo-dev Security 2009-11-14 10:49:08 UTC
+++ This bug was initially created as a clone of Bug #292023 +++

From $URL:
Transport Layer Security (TLS, RFC 5246 and previous, including SSL v3 and previous) is subject to a number of serious man-in-the-middle (MITM) attacks related to renegotiation. In general, these problems allow an MITM to inject an arbitrary amount of chosen plaintext into the beginning of the application protocol stream, leading to a variety of abuse possibilities. In particular, practical attacks against HTTPS client certificate authentication have been demonstrated against recent versions of both Microsoft IIS and Apache httpd on a variety of platforms and in conjunction with a variety of client applications. Cases not involving client certificates have been demonstrated as well. Although this research has focused on the implications specifically for HTTP as the application protocol, the research is ongoing and many of these attacks are expected to generalize well to other protocols layered on TLS.

Discovered by Marsh Ray of PhoneFactor and independently by Martin Rex with SAP.

References:
http://extendedsubset.com/Renegotiating_TLS.pdf
http://www.ietf.org/mail-archive/web/tls/current/msg03928.html
https://bugzilla.redhat.com/show_bug.cgi?id=533125
Comment 1 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-11-14 10:50:16 UTC
Please bump to 1.8.8
Comment 2 Samuli Suominen (RETIRED) gentoo-dev 2010-10-25 16:26:40 UTC
There was never stable version.   3.1.3 is now in Portage and vulnerable copy punted from tree.

Time to close this bug?
Comment 3 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-10-25 16:28:17 UTC
Thanks. Closing noglsa as the package was never stable.