Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 523100 (CVE-2014-7143) - <dev-python/twisted-core-14.0.1: trustRoot not respected in HTTP client
Summary: <dev-python/twisted-core-14.0.1: trustRoot not respected in HTTP client
Status: RESOLVED FIXED
Alias: CVE-2014-7143
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-09-18 08:26 UTC by Agostino Sarubbo
Modified: 2016-12-02 08:40 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-09-18 08:26:11 UTC
From ${URL} :


The twisted security project has identified, fixed, and released a
release fixing a security issue, I would like a CVE assigned:

Title: trustRoot not respected in HTTP client
Reporter: Alex Gaynor and David Reid (Rackspace)
Products: Twisted (14.0 only).
Description:
When specifying the trustRoot (CA store) for the HTTP client, Twisted
did not respect the user's specification, and always used the default
of the platform trust. This means that users attempting to use this
feature to implement certificate pinning, or otherwise restrict the
trust CAs would still have accepted any certificate signed by a CA.

Twisted 14.0.1 has been issued to resolve this issue; (Distributors
should note that this release has failing tests, and that a 14.0.2
release will be issued tomorrow, this does not effect the fix, only
the tests).



@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2016-12-01 16:30:16 UTC
Only v14.x branch was affected because this was the branch when the feature was developed, see https://twistedmatrix.com/trac/ticket/4888.

Affected version hit Gentoo repository via https://sources.gentoo.org/cgi-bin/viewvc.cgi/gentoo-x86/dev-python/twisted-core/twisted-core-14.0.0.ebuild?hideattic=1&view=log

Fixed version appeared via https://sources.gentoo.org/cgi-bin/viewvc.cgi/gentoo-x86/dev-python/twisted-core/twisted-core-14.0.1.ebuild?hideattic=1&view=log

However v14.x branch was already cleaned up via https://gitweb.gentoo.org/repo/gentoo.git/commit/dev-python/twisted-core?id=30aa69ba0c44805daa77f664a35643eed86c697d so nothing left to do for us.


@ Maintainer(s): Security recommends to stabilize v15+ in near future because validating certificates is a must these days and this feature isn't present in the current stable branch. However that's not part of this bug.


@ Security: Please vote!
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2016-12-02 08:40:29 UTC
GLSA Vote: No