New issue
Advanced search Search tips

Issue 766996 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Sep 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 2
Type: Bug-Security



Sign in to add a comment

CrOS: Vulnerability reported in net-nds/openldap

Project Member Reported by vomit.go...@appspot.gserviceaccount.com, Sep 20 2017

Issue description

Automated analysis has detected that the following third party packages have had vulnerabilities publicly reported. 

NOTE: There may be several bugs listed below - in almost all cases, all bugs can be quickly addressed by upgrading to the latest version of the package.

Package Name: net-nds/openldap
Package Version: [cpe:/a:openldap:openldap:2.4.44]

Advisory: CVE-2009-3767
  Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2009-3767
  CVSS severity score: 6.8/10.0
  Confidence: high
  Description:

libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.


 

Comment 1 by palmer@chromium.org, Sep 20 2017

Cc: kerrnel@chromium.org mnissler@chromium.org
Components: Infra
Owner: aga...@chromium.org
agable: Is this related to any thing we use in Chrome Infra? If not, go ahead and close it. Thanks!

Comment 2 by aga...@chromium.org, Sep 21 2017

Status: Fixed (was: Untriaged)
We used to use cygldap (which in turn uses openldap) as a part of lighttpd, but we haven't used lighttpd since at least March: https://chromium-review.googlesource.com/449532

I don't know of any other uses of openldap, and I can't find any.
Project Member

Comment 3 by sheriffbot@chromium.org, Sep 21 2017

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Project Member

Comment 4 by sheriffbot@chromium.org, Dec 28 2017

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 5 by dchan@chromium.org, Jan 22 2018

Status: Archived (was: Fixed)

Comment 6 by dchan@chromium.org, Jan 23 2018

Status: Fixed (was: Archived)

Sign in to add a comment