oss-sec mailing list archives
Re: CVE Request: libsoup 2.32.2 sets ssl trusted flag despite no verification
From: Vincent Danen <vdanen () redhat com>
Date: Mon, 30 Apr 2012 16:34:47 -0600
* [2012-04-24 12:04:24 +0200] Ludwig Nussel wrote:
libsoup 2.32.2 does not verify certificates at all if an application does not explicitly specify a file with trusted root CA's. Since that libsoup version relies on the verification failure to clear the trust flag it always considers ssl connections as trusted in that case. Reference: https://bugzilla.novell.com/show_bug.cgi?id=758431
Are you sure it's just this specific version of libsoup? Looking at the code of earlier versions (such as 2.2.98), the patch noted in your bug would apply (unless there is some other context around it that would make this a non-issue?). Did you look at other versions at all? Thanks for any info. --Vincent Danen / Red Hat Security Response Team
Current thread:
- CVE Request: libsoup 2.32.2 sets ssl trusted flag despite no verification Ludwig Nussel (Apr 24)
- Re: CVE Request: libsoup 2.32.2 sets ssl trusted flag despite no verification Kurt Seifried (Apr 24)
- Re: CVE Request: libsoup 2.32.2 sets ssl trusted flag despite no verification Vincent Danen (Apr 30)
- Re: CVE Request: libsoup 2.32.2 sets ssl trusted flag despite no verification Ludwig Nussel (May 02)
- Re: CVE Request: libsoup 2.32.2 sets ssl trusted flag despite no verification Vincent Danen (May 02)
- Re: CVE Request: libsoup 2.32.2 sets ssl trusted flag despite no verification Ludwig Nussel (May 02)
- Re: CVE Request: libsoup 2.32.2 sets ssl trusted flag despite no verification Marc Deslauriers (Apr 30)