Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 491368 (CVE-2013-6396) - <dev-python/python-swiftclient-{2.0.3,2.1.0}: SSL Certificate Verification Security Issue[OSSA 2014-005] (CVE-2013-6396)
Summary: <dev-python/python-swiftclient-{2.0.3,2.1.0}: SSL Certificate Verification Se...
Status: RESOLVED FIXED
Alias: CVE-2013-6396
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial
Assignee: Gentoo Security
URL: https://secunia.com/advisories/55762/
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-11-15 20:11 UTC by Agostino Sarubbo
Modified: 2014-08-19 23:34 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-11-15 20:11:40 UTC
From ${URL} :

Description

A security issue has been reported in Python swiftclient Module, which can be exploited by 
malicious people to conduct spoofing attacks.

The security issue is caused due to the application not properly verifying the server SSL 
certificate. This can be exploited to e.g. spoof the server via a MitM (Man-in-the-Middle) attack 
and e.g. disclose potentially sensitive information.

The security issue is reported in version 1.8. Other versions may also be affected.


Solution:
No official solution is currently available.

Provided and/or discovered by:
Reported by the vendor.

Original Advisory:
Launchpad:
https://bugs.launchpad.net/python-swiftclient/+bug/1199783


@maintainer(s): since the package has never been marked as stable, we don't need to stabilize it. Please remove the affected versions from the tree.
Comment 1 Agostino Sarubbo gentoo-dev 2013-11-18 13:50:14 UTC
Commit:
https://review.openstack.org/#/c/33473/
Comment 2 Kurt Seifried 2013-11-26 19:04:30 UTC
This has been assigned CVE-2013-6396 as per https://bugzilla.redhat.com/show_bug.cgi?id=1031652
Comment 3 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2014-02-17 19:45:10 UTC
partially fixed (in 2.0.2), unfortuanately it looks like they will not backport...

https://bugs.launchpad.net/python-swiftclient/+bug/1199783/comments/21
Comment 4 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2014-07-08 16:20:24 UTC
fixed (bad versions removed from tree), kthnxbai
Comment 5 Yury German Gentoo Infrastructure gentoo-dev 2014-07-08 16:24:49 UTC
Thank you for your work!

Closing - noglsa
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2014-08-19 23:34:09 UTC
CVE-2013-6396 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6396):
  The OpenStack Python client library for Swift (python-swiftclient) 1.0
  through 1.9.0 does not verify X.509 certificates from SSL servers, which
  allows man-in-the-middle attackers to spoof servers and obtain sensitive
  information via a crafted certificate.