Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 386309 (CVE-2011-0633)

Summary: <dev-perl/libwww-perl-6.30.0: MITM vulnerability (CVE-2011-0633)
Product: Gentoo Security Reporter: GLSAMaker/CVETool Bot <glsamaker>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: perl
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B4 [glsa]
Package list:
Runtime testing required: ---
Bug Depends on:    
Bug Blocks: 357107    

Description GLSAMaker/CVETool Bot gentoo-dev 2011-10-08 14:00:22 UTC
CVE-2011-0633 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0633):
  The Net::HTTPS module in libwww-perl (LWP) before 6.00, as used in
  WWW::Mechanize, LWP::UserAgent, and other products, when running in
  environments that do not set the If-SSL-Cert-Subject header, does not enable
  full validation of SSL certificates by default, which allows remote
  attackers to spoof servers via man-in-the-middle (MITM) attacks involving
  hostnames that are not properly validated.  NOTE: it could be argued that
  this is a design limitation of the Net::HTTPS API, and separate
  implementations should be independently assigned CVE identifiers for not
  working around this limitation. However, because this API was modified
  within LWP, a single CVE identifier has been assigned.
Comment 1 Torsten Veller (RETIRED) gentoo-dev 2011-11-05 09:38:28 UTC
Please stabilize

=dev-perl/libwww-perl-6.30.0
=dev-perl/HTTP-Negotiate-6.0.0
=dev-perl/LWP-Protocol-https-6.20.0
=dev-perl/HTTP-Date-6.0.0
=dev-perl/File-Listing-6.30.0
=dev-perl/WWW-RobotRules-6.10.0
=dev-perl/Net-HTTP-6.10.0
=dev-perl/LWP-MediaTypes-6.10.0
=dev-perl/Encode-Locale-1.20.0
=dev-perl/HTTP-Message-6.20.0
=dev-perl/HTTP-Cookies-6.0.0
=dev-perl/HTTP-Daemon-6.0.0
=dev-perl/IO-Socket-SSL-1.440.0
=dev-perl/HTML-Form-6.0.0
Comment 2 Agostino Sarubbo gentoo-dev 2011-11-05 09:44:20 UTC
all fine on amd64.
Comment 3 Myckel Habets 2011-11-05 18:05:48 UTC
Builds fine on x86. Please mark stable for x86.
Comment 4 Brent Baude (RETIRED) gentoo-dev 2011-11-06 13:16:14 UTC
ppc done
Comment 5 Andreas Schürch gentoo-dev 2011-11-06 14:09:50 UTC
x86 done, thanks Myckel!
Comment 6 Ian Delaney (RETIRED) gentoo-dev 2011-11-06 17:54:39 UTC
amd64:

all ok
Comment 7 Markus Meier gentoo-dev 2011-11-06 22:06:11 UTC
arm stable
Comment 8 Jeroen Roovers (RETIRED) gentoo-dev 2011-11-07 13:14:39 UTC
Stable for HPPA.
Comment 9 Tony Vroon (RETIRED) gentoo-dev 2011-11-08 23:30:30 UTC
+  08 Nov 2011; Tony Vroon <chainsaw@gentoo.org> HTTP-Date-6.0.0.ebuild:
+  Marked stable on AMD64 based on arch testing by Agostino "ago" Sarubbo & Ian
+  "idella4" Delaney in security bug #386309.

+  08 Nov 2011; Tony Vroon <chainsaw@gentoo.org> Encode-Locale-1.20.0.ebuild:
+  Marked stable on AMD64 based on arch testing by Agostino "ago" Sarubbo & Ian
+  "idella4" Delaney in security bug #386309.

+  08 Nov 2011; Tony Vroon <chainsaw@gentoo.org> LWP-MediaTypes-6.10.0.ebuild:
+  Marked stable on AMD64 based on arch testing by Agostino "ago" Sarubbo & Ian
+  "idella4" Delaney in security bug #386309.

+  08 Nov 2011; Tony Vroon <chainsaw@gentoo.org> HTTP-Message-6.20.0.ebuild:
+  Marked stable on AMD64 based on arch testing by Agostino "ago" Sarubbo & Ian
+  "idella4" Delaney in security bug #386309.

+  08 Nov 2011; Tony Vroon <chainsaw@gentoo.org> HTTP-Negotiate-6.0.0.ebuild:
+  Marked stable on AMD64 based on arch testing by Agostino "ago" Sarubbo & Ian
+  "idella4" Delaney in security bug #386309.

+  08 Nov 2011; Tony Vroon <chainsaw@gentoo.org> File-Listing-6.30.0.ebuild:
+  Marked stable on AMD64 based on arch testing by Agostino "ago" Sarubbo & Ian
+  "idella4" Delaney in security bug #386309.

+  08 Nov 2011; Tony Vroon <chainsaw@gentoo.org> HTTP-Cookies-6.0.0.ebuild:
+  Marked stable on AMD64 based on arch testing by Agostino "ago" Sarubbo & Ian
+  "idella4" Delaney in security bug #386309.

+  08 Nov 2011; Tony Vroon <chainsaw@gentoo.org> HTTP-Daemon-6.0.0.ebuild:
+  Marked stable on AMD64 based on arch testing by Agostino "ago" Sarubbo & Ian
+  "idella4" Delaney in security bug #386309.

+  08 Nov 2011; Tony Vroon <chainsaw@gentoo.org> WWW-RobotRules-6.10.0.ebuild:
+  Marked stable on AMD64 based on arch testing by Agostino "ago" Sarubbo & Ian
+  "idella4" Delaney in security bug #386309.

+  08 Nov 2011; Tony Vroon <chainsaw@gentoo.org> Net-HTTP-6.10.0.ebuild:
+  Marked stable on AMD64 based on arch testing by Agostino "ago" Sarubbo & Ian
+  "idella4" Delaney in security bug #386309.

+  08 Nov 2011; Tony Vroon <chainsaw@gentoo.org> IO-Socket-SSL-1.440.0.ebuild:
+  Marked stable on AMD64 based on arch testing by Agostino "ago" Sarubbo & Ian
+  "idella4" Delaney in security bug #386309.

+  08 Nov 2011; Tony Vroon <chainsaw@gentoo.org>
+  LWP-Protocol-https-6.20.0.ebuild:
+  Marked stable on AMD64 based on arch testing by Agostino "ago" Sarubbo & Ian
+  "idella4" Delaney in security bug #386309.

+  08 Nov 2011; Tony Vroon <chainsaw@gentoo.org> libwww-perl-6.30.0.ebuild:
+  Marked stable on AMD64 based on arch testing by Agostino "ago" Sarubbo & Ian
+  "idella4" Delaney in security bug #386309.

Consideration of dependency order would be appreciated in future bugs, particularly with stabilisation lists of this length.
Comment 10 Raúl Porcel (RETIRED) gentoo-dev 2011-11-19 19:59:18 UTC
alpha/ia64/m68k/s390/sh/sparc stable
Comment 11 Mark Loeser (RETIRED) gentoo-dev 2011-12-18 21:37:24 UTC
ppc64 done
Comment 12 Tim Sammut (RETIRED) gentoo-dev 2011-12-18 21:51:17 UTC
Thanks, folks. GLSA Vote: yes.
Comment 13 Stefan Behte (RETIRED) gentoo-dev Security 2012-03-06 01:04:52 UTC
Vote: Yes. GLSA request filed.
Comment 14 GLSAMaker/CVETool Bot gentoo-dev 2014-02-04 16:33:10 UTC
This issue was resolved and addressed in
 GLSA 201402-04 at http://security.gentoo.org/glsa/glsa-201402-04.xml
by GLSA coordinator Mikle Kolyada (Zlogene).