Giuseppe Iuculano
2009-Oct-31 09:57 UTC
[Secure-testing-team] Bug#553432: CVE-2009-3767: Doesn''t properly handle NULL character in subject Common Name
Package: openldap Severity: grave Tags: security patch -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for openldap. CVE-2009-3767[0]: | libraries/libldap/tls_o.c in OpenLDAP, when OpenSSL is used, does not | properly handle a ''\0'' character in a domain name in the subject''s | Common Name (CN) field of an X.509 certificate, which allows | man-in-the-middle attackers to spoof arbitrary SSL servers via a | crafted certificate issued by a legitimate Certification Authority, a | related issue to CVE-2009-2408. Please coordinate with the security team (team at security.debian.org) to prepare packages for the stable and oldstable releases. If you fix the vulnerability please also make sure to include the CVE id in your changelog entry. For further information see: [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3767 http://security-tracker.debian.org/tracker/CVE-2009-3767 Patch: http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_o.c.diff?r1=1.8&r2=1.11&f=h -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAkrsCe4ACgkQNxpp46476aqyOwCfYvjBZj45odwhQLQ7eeFCT9j4 YDcAnjvkFab1GOwO9tv/6iXVVqCW5D/g =0E+p -----END PGP SIGNATURE-----