Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 386637 - <dev-libs/matrixssl-3.2.2 Initialization Vector Selection Vulnerability
Summary: <dev-libs/matrixssl-3.2.2 Initialization Vector Selection Vulnerability
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: http://www.matrixssl.org/archives/000...
Whiteboard: ~3 [noglsa]
Keywords:
: 387277 (view as bug list)
Depends on:
Blocks:
 
Reported: 2011-10-10 11:33 UTC by Sean Amoss (RETIRED)
Modified: 2011-10-16 07:09 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
ebuild.patch (diff,1.82 KB, patch)
2011-10-10 12:23 UTC, Agostino Sarubbo
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Sean Amoss (RETIRED) gentoo-dev Security 2011-10-10 11:33:15 UTC
From the upstream notification at $URL:

"In Sept. 2011 security researchers demonstrated how a previously known CBC encryption weakness could be used to decrypt HTTP data over SSL. The attack was named BEAST (Browser Exploit Against SSL/TLS). As with previous man-in-the-middle SSL vulnerabilities, the attack is generally considered a very low risk for individual browsers as it requires the attacker to have control over the network. Additionally, in this specific exploit they will also have to have a mechanism to elicit known HTTPS responses from the client. Most MatrixSSL users do not fall into the category of vulnerable uses."
Comment 1 Agostino Sarubbo gentoo-dev 2011-10-10 12:23:51 UTC
Created attachment 289441 [details, diff]
ebuild.patch

@embedded, same ebuild works for me, added eapi4 and static-libs, please review and commit.
SONAME is not a regression
Comment 2 Agostino Sarubbo gentoo-dev 2011-10-10 16:29:46 UTC
3.2.2 in tree, thanks ssuominen for bump.

Closing as noglsa.
Comment 3 Samuli Suominen (RETIRED) gentoo-dev 2011-10-16 07:07:40 UTC
*** Bug 387277 has been marked as a duplicate of this bug. ***
Comment 4 Samuli Suominen (RETIRED) gentoo-dev 2011-10-16 07:09:06 UTC
For completeness, I've removed the vulnerable version from tree.