Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 387273 - net-im/psi-0.14.0 Certificate Text Format Enforce Vulnerability
Summary: net-im/psi-0.14.0 Certificate Text Format Enforce Vulnerability
Status: RESOLVED DUPLICATE of bug 384227
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://archives.neohapsis.com/archive...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-10-16 06:42 UTC by Michael Harrison
Modified: 2011-10-16 17:32 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Harrison 2011-10-16 06:42:38 UTC
The vulnerability is caused due to Psi not properly setting the text format when displaying certificate information, which can be exploited to spoof certificates via e.g. certificates containing specially crafted RTF data in the Common Name (CN) field.

Reference:
CVE-2011-{3365,3366,3367}
Comment 1 Agostino Sarubbo gentoo-dev 2011-10-16 13:19:17 UTC

*** This bug has been marked as a duplicate of bug 384227 ***
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2011-10-16 14:35:27 UTC
Michael and Agostino. Will psi require its own fix, so should this bug stay open? If not, do we need to request a fixed version of psi in bug 384227? Tnx.
Comment 3 Agostino Sarubbo gentoo-dev 2011-10-16 14:48:29 UTC
Tim, imho psi appears a bit dead upstream. Last version was out in dec 2009.

A better solution should be: if upstream does not care in a a time established by us, or maintainers/anyone does not produce a patch, we can drop it from main tree.

I'll talk with maintainer
Comment 4 Michael Harrison 2011-10-16 17:32:11 UTC
Thanks Ago, it looked like it might be a separate fix to me, but wasn't sure, so I just referenced the other CVEs.