Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 503394 (CVE-2014-0092) - <net-libs/gnutls-2.12.23-r4: Unspecified Certificate Verification Vulnerabilities (CVE-2014-0092) [GNUTLS-SA-2014-2]
Summary: <net-libs/gnutls-2.12.23-r4: Unspecified Certificate Verification Vulnerabili...
Status: RESOLVED FIXED
Alias: CVE-2014-0092
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/56872/
Whiteboard: A3 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-03-04 09:40 UTC by Agostino Sarubbo
Modified: 2016-08-11 11:17 UTC (History)
7 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-03-04 09:40:36 UTC
From ${URL} :

Description

Some vulnerabilities have been reported in GnuTLS, which can be exploited by malicious people to conduct 
spoofing attacks.

The vulnerabilities are caused due to some unspecified errors when verifying certificates and can be 
exploited to bypass certain certificate validation checks and subsequently e.g. spoof a server.

The vulnerabilities are reported in versions 3.x prior to 3.2.12 and prior to 3.1.22 and versions 2.x.


Solution:
Update to a fixed version or apply patch.

Further details available to Secunia VIM customers

Provided and/or discovered by:
Reported by the vendor.

Original Advisory:
GnuTLS:
http://gnutls.org/security.html#GNUTLS-SA-2014-2
http://lists.gnutls.org/pipermail/gnutls-devel/2014-March/006794.html
http://lists.gnutls.org/pipermail/gnutls-devel/2014-March/006795.html


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Hanno Böck gentoo-dev 2014-03-04 13:04:38 UTC
3.12.2 is already in the tree, but ~-only. For gnutls 2.x, there's no update available, but a patch from upstream.

So we need either a patched 2.x-ebuild or stabilize 3.12.2.
Comment 2 Alon Bar-Lev gentoo-dev 2014-03-04 15:43:49 UTC
gnutls-2.12.23-r3 in tree with patch[1]

[1] https://www.gitorious.org/gnutls/gnutls/commit/6aa26f78150ccbdf0aec1878a41c17c41d358a3b
Comment 3 Yury German Gentoo Infrastructure gentoo-dev Security 2014-03-04 16:12:17 UTC
Please advise when testing is complete and you are ready for stabilization.
Comment 4 Alon Bar-Lev gentoo-dev 2014-03-04 16:18:23 UTC
(In reply to Yury German from comment #3)
> Please advise when testing is complete and you are ready for stabilization.

FEATURES="test" is ok. best that stable teams will test it more.
Comment 5 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2014-03-04 16:45:03 UTC
CC arches then?
Comment 6 Alon Bar-Lev gentoo-dev 2014-03-04 19:51:21 UTC
Please stabilize: gnutls-2.12.23-r3

Thanks!
Comment 7 Alon Bar-Lev gentoo-dev 2014-03-04 20:27:31 UTC
(In reply to Alon Bar-Lev from comment #6)
> Please stabilize: gnutls-2.12.23-r3
> 
> Thanks!

Sorry, yet another CVE at bug#501282, please stabilize gnutls-2.12.23-r4 which contains both.

Thanks!
Comment 8 Jeroen Roovers gentoo-dev 2014-03-05 14:21:44 UTC
Stable for HPPA.
Comment 9 Richard Freeman gentoo-dev 2014-03-05 17:59:07 UTC
amd64 stable
Comment 10 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2014-03-08 17:20:48 UTC
x86 stable
Comment 11 Agostino Sarubbo gentoo-dev 2014-03-12 10:37:38 UTC
sparc stable
Comment 12 Agostino Sarubbo gentoo-dev 2014-03-16 11:08:17 UTC
ppc stable
Comment 13 Agostino Sarubbo gentoo-dev 2014-03-18 16:08:14 UTC
ia64 stable
Comment 14 Agostino Sarubbo gentoo-dev 2014-03-19 14:14:04 UTC
alpha stable
Comment 15 Markus Meier gentoo-dev 2014-03-22 21:32:47 UTC
arm stable
Comment 16 Agostino Sarubbo gentoo-dev 2014-03-24 14:29:27 UTC
ppc64 stable.

Maintainer(s), please cleanup.
Security, please add it to the existing request, or file a new one.
Comment 17 Yury German Gentoo Infrastructure gentoo-dev Security 2014-03-24 21:54:55 UTC
Arches, Thank you for your work
Maintainer(s), please drop the vulnerable version.

Created a new GLSA request.
Comment 18 Yury German Gentoo Infrastructure gentoo-dev Security 2014-05-15 04:33:08 UTC
Maintainer(s), please drop the vulnerable version.
Comment 19 Yury German Gentoo Infrastructure gentoo-dev Security 2014-05-20 03:34:22 UTC
Maintainer(s), Thank you for cleanup!
Comment 20 GLSAMaker/CVETool Bot gentoo-dev 2014-06-10 07:51:41 UTC
CVE-2014-0092 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0092):
  lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not
  properly handle unspecified errors when verifying X.509 certificates from
  SSL servers, which allows man-in-the-middle attackers to spoof servers via a
  crafted certificate.
Comment 21 GLSAMaker/CVETool Bot gentoo-dev 2014-06-13 19:52:04 UTC
This issue was resolved and addressed in
 GLSA 201406-09 at http://security.gentoo.org/glsa/glsa-201406-09.xml
by GLSA coordinator Mikle Kolyada (Zlogene).