Red Hat Certificate System CSR Extension Handling Bug May Let Users Bypass Security Policy
|
|
SecurityTracker Alert ID: 1020427
|
|
SecurityTracker URL: http://securitytracker.com/id?1020427
|
|
CVE Reference: CVE-2008-1676
(Links to External Site)
|
Date: Jul 2 2008
|
Impact: Modification of user information
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Red Hat Advisory
|
Version(s): 7.3
|
Description: A vulnerability was reported in Red Hat Certificate System. A user may be able to bypass certificate signing policies.
The system will add all Extensions requested in certificate signing requests (CSR) to the generated subordinate Certificate Authority
(CA) certificate, even if the CA profile contains constraints that prohibit subordinate CA certificates.
This may simplify man-in-the-middle
attacks against users that trust Certificate Authorities managed by Red Hat Certificate System.
|
Impact: A user may be able to bypass certificate signing policies.
|
Solution: Red Hat has issued a fix for rhpki-common.
The Red Hat advisory is available at:
https://rhn.redhat.com/errata/RHSA-2008-0500.html
|
Vendor URL: rhn.redhat.com/errata/RHSA-2008-0500.html (Links to External Site)
|
Cause: Access control error
|
Underlying OS: Linux (Red Hat Enterprise)
|
Reported By: bugzilla@redhat.com
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Wed, 2 Jul 2008 13:56:32 -0400
From: bugzilla@redhat.com
Subject: [RHSA-2008:0500-01] Important: rhpki-common security update
|
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
=====================================================================
Red Hat Security Advisory
Synopsis: Important: rhpki-common security update
Advisory ID: RHSA-2008:0500-01
Product: Red Hat Certificate System
Advisory URL: https://rhn.redhat.com/errata/RHSA-2008-0500.html
Issue date: 2008-07-02
CVE Names: CVE-2008-1676
=====================================================================
1. Summary:
An updated rhpki-common package that fixes a security issue is now available
for Red Hat Certificate System 7.3.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
2. Relevant releases/architectures:
Red Hat Certificate System 7.3 for 4AS - noarch
Red Hat Certificate System 7.3 for 4ES - noarch
3. Description:
Red Hat Certificate System (RHCS) is an enterprise software system designed
to manage enterprise Public Key Infrastructure (PKI) deployments.
rhpki-common -- the Red Hat PKI Common Framework -- is required by the
following four RHCS subsystems: the Red Hat Certificate Authority; the Red
Hat Data Recovery Manager; the Red Hat Online Certificate Status Protocol
Manager; and the Red Hat Token Key Service.
A flaw was found in the way Red Hat Certificate System handled Extensions
in the certificate signing requests (CSR). All requested Extensions were
added to the issued certificate even if constraints were defined in the
Certificate Authority (CA) profile. An attacker could submit a CSR for a
subordinate CA certificate even if the CA configuration prohibited
subordinate CA certificates. This lead to a bypass of the intended security
policy, possibly simplifying man-in-the-middle attacks against users that
trust Certificate Authorities managed by Red Hat Certificate System.
(CVE-2008-1676)
All users of Red Hat Certificate System 7.3 should upgrade to this
updated package, which resolves this issue.
4. Solution:
Users running Red Hat Certificate System on Red Hat Enterprise Linux:
Before applying this update, make sure that all previously-released errata
relevant to your system have been applied.
This update is available via Red Hat Network. Details on how to use the Red
Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188
Users running Red Hat Certificate System on Sun Solaris:
An updated Solaris packages in .pkg format are available in the Red Hat
Certificate System Solaris channels on the Red Hat Network. This packages
should be installed/upgraded using Solaris native package management tools.
See also Red Hat Certificate System Administration Guide for installation
instructions:
http://www.redhat.com/docs/manuals/cert-system/
5. Bugs fixed (http://bugzilla.redhat.com/):
445227 - CVE-2008-1676 Certificate System: incorrect handling of Extensions in CSRs
6. Package List:
Red Hat Certificate System 7.3 for 4AS:
noarch:
rhpki-common-7.3.0-29.el4.noarch.rpm
Red Hat Certificate System 7.3 for 4ES:
noarch:
rhpki-common-7.3.0-29.el4.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://www.redhat.com/security/team/key/#package
7. References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1676
http://www.redhat.com/security/updates/classification/#important
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://www.redhat.com/security/team/contact/
Copyright 2008 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (GNU/Linux)
iD8DBQFIa8EnXlSAg2UNWIIRAlIPAKCJTcayaS35w+4Cs18OSzf7OUkBeQCgl5+t
LSTdb4tdBvO2ErlZBuFDxx0=
=YI5n
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce
|
|