Bug 797033 (CVE-2011-4968) - VUL-1: nginx: http proxy module does not verify peer identity of https origin server
Summary: VUL-1: nginx: http proxy module does not verify peer identity of https origin...
Status: RESOLVED FIXED
Alias: CVE-2011-4968
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Normal
Target Milestone: ---
Assignee: Stefan Schubert
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-01-07 14:22 UTC by Sebastian Krahmer
Modified: 2015-02-18 07:57 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Krahmer 2013-01-07 14:22:56 UTC
Via oss-sec:

Date: Thu, 03 Jan 2013 10:36:20 -0500
From: Daniel Kahn Gillmor 
To: oss-security

nginx offers the ability for its http proxy module to talk to an origin
server over https.  However, it does not verify the identity of the
origin server in this case, which leaves it subject to MITM attacks
between the proxy and the origin server.

Sadly, this appears to be unfixed for over a year after it was first
reported:

 http://trac.nginx.org/nginx/ticket/13

some patch review starts over here, but doesn't seem to reach any
resolution:

 http://mailman.nginx.org/pipermail/nginx-devel/2011-September/001182.html

As far as i can tell, there is no CVE assigned for this yet.

        --dkg
Comment 1 Sebastian Krahmer 2013-01-07 14:23:35 UTC
CVE-2011-4968

Probably something for factory.
Comment 2 Swamp Workflow Management 2013-01-07 23:00:26 UTC
bugbot adjusting priority
Comment 3 Victor Pereira 2015-02-16 15:08:30 UTC
we have it just in opensuse and its already fixed.
Comment 4 Marcus Meissner 2015-02-18 07:57:28 UTC
No, nginx is also on SLE

nginx-0.8 and nginx-1.0nginx-1.0