Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Tue, 24 Apr 2012 12:04:24 +0200
From: Ludwig Nussel <ludwig.nussel@...e.de>
To: oss-security@...ts.openwall.com
Cc: Vincent Untz <vuntz@...e.com>
Subject: CVE Request: libsoup 2.32.2 sets ssl trusted flag despite no verification

Hi,

libsoup 2.32.2 does not verify certificates at all if an application does
not explicitly specify a file with trusted root CA's. Since that libsoup
version relies on the verification failure to clear the trust flag it
always considers ssl connections as trusted in that case.

Reference:
https://bugzilla.novell.com/show_bug.cgi?id=758431

cu
Ludwig

-- 
 (o_   Ludwig Nussel
 //\
 V_/_  http://www.suse.de/
SUSE LINUX Products GmbH, GF: Jeff Hawn, Jennifer Guild, Felix Imendörffer, HRB 16746 (AG Nürnberg) 

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.