Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 445172 (CVE-2012-5582) - <net-dns/opendnssec-1.4.7: insecure usage of curl (CVE-2012-5582)
Summary: <net-dns/opendnssec-1.4.7: insecure usage of curl (CVE-2012-5582)
Status: RESOLVED FIXED
Alias: CVE-2012-5582
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-11-29 11:33 UTC by Agostino Sarubbo
Modified: 2016-03-24 07:19 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2012-11-29 11:33:56 UTC
From $URL :

Hi,
during the triage of the SSL client bugs spotted by the
http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf paper
Debian developer Alessandro Ghedini discovered two more
applications using Curl in an insecure manner:

1. opendnssec (in the eppclient tool)
http://lists.opendnssec.org/pipermail/opendnssec-user/2012-November/002296.html
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2016-03-18 08:30:39 UTC
Per the release notes[0] eppclient has been removed since 1.4.0rc1.

@maintainer, please cleanup vulnerable ebuilds (<1.4.7).

[0]: https://github.com/opendnssec/opendnssec/blob/7e0ca962fb219f13842174b2984fbcb3ffb7b171/NEWS#L229
Comment 2 Marc Schiffbauer gentoo-dev 2016-03-24 00:33:53 UTC
I cleaned it up and pushed a patched version (1.3.18-r1).

Would be good if you reviewed the patch: files/opendnssec-1.3.18-eppclient-curl-CVE-2012-5582.patch

TIA ;)
Comment 3 Aaron Bauman (RETIRED) gentoo-dev 2016-03-24 07:19:38 UTC
(In reply to Marc Schiffbauer from comment #2)
> I cleaned it up and pushed a patched version (1.3.18-r1).
> 
> Would be good if you reviewed the patch:
> files/opendnssec-1.3.18-eppclient-curl-CVE-2012-5582.patch
> 
> TIA ;)

Marc, looks good to me :)  Thanks for the fix and bump.