Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 494158 (CVE-2013-7110) - <app-i18n/transifex-client-0.10: Does not validate HTTPS server certificate (incomplete fix for CVE-2013-2073) (CVE-2013-7110)
Summary: <app-i18n/transifex-client-0.10: Does not validate HTTPS server certificate (...
Status: RESOLVED FIXED
Alias: CVE-2013-7110
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-12-13 15:46 UTC by Agostino Sarubbo
Modified: 2015-03-18 17:56 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-12-13 15:46:04 UTC
From ${URL} :

The way certificate check was implemented to fix CVE-2013-2073 was
incorrect (check was done on "probe" connection, but not the actual
connection used to transfer data).  This should now be fixed in 0.10
(I can't confirm atm), which switches to use urllib3 with proper
certificate checks.

https://github.com/transifex/transifex-client/issues/42
https://github.com/transifex/transifex-client/commit/6d69d61



@maintainer(s): since the fixed package is already in the tree, please let us know if it is ready for the stabilization or not.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2015-01-03 17:01:13 UTC
CVE-2013-7110 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-7110):
  Transifex command-line client before 0.10 does not validate X.509
  certificates for data transfer connections, which allows man-in-the-middle
  attackers to spoof a Transifex server via an arbitrary certificate.  NOTE:
  this vulnerability exists because of an incomplete fix for CVE-2013-2073.
Comment 2 Sean Amoss (RETIRED) gentoo-dev Security 2015-01-03 17:03:31 UTC
GLSA vote: no.
Comment 3 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2015-03-18 17:56:15 UTC
GLSA vote: no.

Closing as [noglsa]