Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 492688 (CVE-2013-4545) - <net-misc/curl-7.33.0 : Man-in-the-Middle attack (CVE-2013-4545)
Summary: <net-misc/curl-7.33.0 : Man-in-the-Middle attack (CVE-2013-4545)
Status: RESOLVED FIXED
Alias: CVE-2013-4545
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A4 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-11-27 10:37 UTC by GLSAMaker/CVETool Bot
Modified: 2014-01-20 14:11 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2013-11-27 10:37:35 UTC
CVE-2013-4545 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4545):
  cURL and libcurl 7.18.0 through 7.32.0, when built with OpenSSL, disables
  the certificate CN and SAN name field verification (CURLOPT_SSL_VERIFYHOST)
  when the digital signature verification (CURLOPT_SSL_VERIFYPEER) is
  disabled, which allows man-in-the-middle attackers to spoof SSL servers via
  an arbitrary valid certificate.
Comment 1 Anthony Basile gentoo-dev 2013-12-18 15:42:28 UTC
Let's stabilize curl-7.33.0.  It has been in the tree since Oct 15 and no bugs.

Keywords for net-misc/curl:
          |                           | u   |  
          | a a             p     s   | n   |  
          | l m   h i m m   p s   p   | u s | r
          | p d a p a 6 i p c 3   a x | s l | e
          | h 6 r p 6 8 p p 6 9 s r 8 | e o | p
          | a 4 m a 4 k s c 4 0 h c 6 | d t | o
----------+---------------------------+-----+-------
[I]7.31.0 | + + + + + o ~ + + + + + + | o 0 | gentoo
   7.33.0 | ~ ~ ~ ~ ~ o ~ ~ ~ ~ ~ ~ ~ | #   | gentoo
   7.34.0 | ~ ~ ~ ~ ~ o ~ ~ ~ ~ ~ ~ ~ | o   | gentoo


TARGET="alpha amd64 arm hppa ia64 ppc ppc64 sparc x86"

sh and s390 are now ~arch only.  I'm cc-ing them to alert that we are leaving KEYWORDS="~s390 ~sh" when I remove 7.31.0.  Remove yourselves from the CC list if you are okay with that.
Comment 2 Jeroen Roovers (RETIRED) gentoo-dev 2013-12-19 13:49:45 UTC
Stable for HPPA.
Comment 3 Anthony Basile gentoo-dev 2013-12-20 01:10:04 UTC
stable ppc and ppc64
Comment 4 Anthony Basile gentoo-dev 2013-12-22 16:24:32 UTC
Stable arm
Comment 5 Pacho Ramos gentoo-dev 2013-12-22 19:01:07 UTC
amd64 stable
Comment 6 Agostino Sarubbo gentoo-dev 2013-12-23 14:26:03 UTC
alpha stable
Comment 7 Agostino Sarubbo gentoo-dev 2013-12-23 14:48:50 UTC
x86 stable
Comment 8 Agostino Sarubbo gentoo-dev 2013-12-23 14:53:02 UTC
sparc stable
Comment 9 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2013-12-26 19:43:17 UTC
ia64 stable. 

Added to existing glsa drfat.

Maintainer(s), please cleanup.
Comment 10 Anthony Basile gentoo-dev 2013-12-26 23:15:23 UTC
(In reply to Mikle Kolyada from comment #9)
> ia64 stable. 
> 
> Added to existing glsa drfat.
> 
> Maintainer(s), please cleanup.

Cleanup done.
Comment 11 GLSAMaker/CVETool Bot gentoo-dev 2014-01-20 14:11:28 UTC
This issue was resolved and addressed in
 GLSA 201401-14 at http://security.gentoo.org/glsa/glsa-201401-14.xml
by GLSA coordinator Sergey Popov (pinkbyte).