Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 199191 (CVE-2007-5770) - dev-lang/ruby < 1.8.6_p111 SSL commonName (CN) verficiation in Net::ftptls, telnets, imap, pop, smtp (CVE-2007-5770)
Summary: dev-lang/ruby < 1.8.6_p111 SSL commonName (CN) verficiation in Net::ftptls, t...
Status: RESOLVED FIXED
Alias: CVE-2007-5770
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://svn.ruby-lang.org/cgi-bin/view...
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-11-14 23:17 UTC by Robert Buchholz (RETIRED)
Modified: 2020-04-03 22:49 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2007-11-14 23:17:06 UTC
CVE-2007-5770 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5770):
  The (1) Net::ftptls, (2) Net::telnets, (3) Net::imap, (4) Net::pop, and (5)
  Net::smtp libraries in Ruby 1.8.5 and 1.8.6 do not verify that the commonName
  (CN) field in a server certificate matches the domain name in a request sent
  over SSL, which makes it easier for remote attackers to intercept SSL
  transmissions via a man-in-the-middle attack or spoofed web site, different
  components than CVE-2007-5162.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2007-11-14 23:19:18 UTC
Ruby, can you confirm that these modules were fixed in the update in bug 194236 or do they need additional patching?
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2007-11-20 00:48:45 UTC
ruby, please advise.
Comment 3 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-12-08 23:54:07 UTC
(In reply to comment #2)
> ruby, please advise.
> 

*ping*
Comment 4 Hans de Graaff gentoo-dev Security 2007-12-09 09:59:36 UTC
Sorry for the delay. Richard has been working on this but he has not been online for several weeks now, and I don't know much about this.

Judging from the redhat report this issue is similar to bug 194236 but for the other services using SSL. So: more patching is needed. Redhat bug https://bugzilla.redhat.com/show_bug.cgi?id=362081 seems to be the patch required. 
Comment 5 Richard Brown (RETIRED) gentoo-dev 2007-12-09 17:43:19 UTC
The patch linked is against ruby trunk, not the 1.8 branch, I've sent an email to ruby-core to see what they say. Sorry for the delay.
Comment 6 Richard Brown (RETIRED) gentoo-dev 2007-12-23 10:45:03 UTC
I've added =dev-lang/ruby-1.8.6_p111. Arches please stabilise.
Comment 7 Markus Meier gentoo-dev 2007-12-23 13:46:27 UTC
x86 stable
Comment 8 Brent Baude (RETIRED) gentoo-dev 2007-12-23 17:16:11 UTC
ppc and ppc64 done
Comment 9 Jeroen Roovers (RETIRED) gentoo-dev 2007-12-24 02:39:00 UTC
dev-lang/ruby-1.8.6_p111-r1 marked stable for HPPA.
Comment 10 Richard Brown (RETIRED) gentoo-dev 2007-12-24 08:36:11 UTC
Just to be clear I was asking for 1.8.6_p111 to be stabled, not 1.8.6_p111-r1. Jer, I've added hppa back so you see this, but I don't think the world is going to end, -r1 has some more bugfixes from upstream and the ebuild has been reworked a little, but should still be basically fine. -r0 specifically only has the security changes in it.
Comment 11 Jeroen Roovers (RETIRED) gentoo-dev 2007-12-24 14:55:22 UTC
(In reply to comment #10)
> Just to be clear I was asking for 1.8.6_p111 to be stabled

So I told exactly which version I stabled. :)
I can mark -r0 for you as well if you like...
Comment 12 Raúl Porcel (RETIRED) gentoo-dev 2007-12-24 15:31:11 UTC
alpha/ia64/sparc stable
Comment 13 Peter Weller (RETIRED) gentoo-dev 2007-12-26 09:05:09 UTC
amd64 stable
Comment 14 Tobias Heinlein (RETIRED) gentoo-dev 2007-12-26 11:41:09 UTC
All supported arches done, vote now.
Comment 15 Robert Buchholz (RETIRED) gentoo-dev 2007-12-26 12:05:16 UTC
Similar to the issue in bug 194236, voting NO.
Comment 16 Stefan Cornelius (RETIRED) gentoo-dev 2007-12-26 21:57:18 UTC
tend to say no
Comment 17 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-12-28 23:37:52 UTC
no too, closing.