Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 450288 (CVE-2011-4968) - <www-servers/nginx-1.7.4: http proxy module does not verify peer identity of https origin server (CVE-2011-4968)
Summary: <www-servers/nginx-1.7.4: http proxy module does not verify peer identity of ...
Status: RESOLVED FIXED
Alias: CVE-2011-4968
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-01-04 19:53 UTC by Agostino Sarubbo
Modified: 2016-05-21 12:35 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-01-04 19:53:34 UTC
From $URL :

nginx offers the ability for its http proxy module to talk to an origin
server over https.  However, it does not verify the identity of the
origin server in this case, which leaves it subject to MITM attacks
between the proxy and the origin server.

Sadly, this appears to be unfixed for over a year after it was first
reported:

 http://trac.nginx.org/nginx/ticket/13

some patch review starts over here, but doesn't seem to reach any
resolution:

 http://mailman.nginx.org/pipermail/nginx-devel/2011-September/001182.html

As far as i can tell, there is no CVE assigned for this yet.
Comment 1 Kristian Fiskerstrand (RETIRED) gentoo-dev 2014-06-17 22:15:31 UTC
This appears to be fixed in 1.7.0 . From http://nginx.org/en/CHANGES : 
    *) Feature: backend SSL certificate verification.
    *) Feature: support for SNI while working with SSL backends.

See also: 
http://trac.nginx.org/nginx/ticket/13
http://trac.nginx.org/nginx/changeset/060c2e692b96a150b584b8e30d596be1f2defa9c/nginx
Comment 2 Kristian Fiskerstrand (RETIRED) gentoo-dev 2014-08-17 17:47:56 UTC
nginx 1.7.4 is now the only ebuild in the tree. 

@Security, please vote on GLSA
Comment 3 Yury German Gentoo Infrastructure gentoo-dev 2014-08-19 03:37:42 UTC
GLSA Vote: No
Comment 4 Kristian Fiskerstrand (RETIRED) gentoo-dev 2014-08-19 07:45:13 UTC
GLSA Vote: No