Bug 825876 (CVE-2013-2191) - VUL-0: python-bugzilla: CVE-2013-2191: no server certificate verification
Summary: VUL-0: python-bugzilla: CVE-2013-2191: no server certificate verification
Status: RESOLVED FIXED
Alias: CVE-2013-2191
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-06-20 02:02 UTC by Alexander Bergmann
Modified: 2013-07-11 06:00 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2013-06-20 02:02:09 UTC
Public via oss-security:

Date: Wed, 19 Jun 2013 12:58:40 -0400 (EDT)
From: Jan Lieskovsky
Subject: [oss-security] [CVE identifier assignment notification] CVE-2013-2191 python-bugzilla: Does not verify Bugzilla server certificate

It was found that python-bugzilla, a Python library for interacting with Bugzilla instances over XML-RPC functionality, did not perform X.509 certificate verification when using secured SSL connection. A man-in-the-middle (MiTM) attacker could use this flaw to spoof Bugzilla server via an arbitrary certificate.

Credit: This issue was discovered by Florian Weimer of the Red Hat Product Security Team.

CVE id: CVE-2013-2191 has been assigned to this issue

Relevant upstream patch:
  https://git.fedorahosted.org/cgit/python-bugzilla.git/commit/?id=a782282ee479ba4cc1b8b1d89700ac630ba83eef

References:
  https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-2191
Comment 1 Sascha Peilicke 2013-06-20 08:08:48 UTC
@jan: Have fun
Comment 2 Swamp Workflow Management 2013-06-20 16:00:10 UTC
bugbot adjusting priority
Comment 3 Jan Matejek 2013-06-24 10:35:09 UTC
AFAICT, upstream is days from releasing 0.9.0
i'll wait with Factory update for that

do we want backports for old distributions?
Comment 4 Alexander Bergmann 2013-06-27 01:36:40 UTC
We need to get this fixed for openSUSE (12.2/12.3). 

Is a backport for this feasible from your point of view?
Comment 5 Alexander Bergmann 2013-06-27 02:03:27 UTC
0.9.0 is out by the way.

https://fedorahosted.org/releases/p/y/python-bugzilla/python-bugzilla-0.9.0.tar.gz
Comment 6 Jan Matejek 2013-06-27 10:54:12 UTC
New version submitted to Factory. I'd like a version update for 12.3 also, if possible.

For 12.2... well. Backport of upstream solution is definitely not feasible (too many changes between 0.6 and 0.9), but i might be able to fix the bug in a different way. And of course, if we could do a version update too, that would be nice ;e)
Comment 7 Bernhard Wiedemann 2013-06-27 11:00:20 UTC
This is an autogenerated message for OBS integration:
This bug (825876) was mentioned in
https://build.opensuse.org/request/show/181190 Factory / python-bugzilla
Comment 8 Alexander Bergmann 2013-06-28 01:04:19 UTC
From the maintenance side a version update is possible, _BUT_ it should not change existing functionality so that e.g. the current use of python-bugzilla inside scripts would break. 

What is your assessment of the functional stability?

Iff it is stable then please provide submissions for 12.2 and 12.3.
Comment 9 Jan Matejek 2013-06-28 02:23:21 UTC
Oh, that makes sense. There is a high risk of backwards-incompatible changes, so i'll just fix this withou version update.
Comment 10 Jan Matejek 2013-06-28 05:36:27 UTC
submitted patches to 12.3 and 12.2, handing over to security
Comment 11 Bernhard Wiedemann 2013-06-28 06:00:26 UTC
This is an autogenerated message for OBS integration:
This bug (825876) was mentioned in
https://build.opensuse.org/request/show/181324 Maintenance / 
https://build.opensuse.org/request/show/181325 Maintenance /
Comment 12 Bernhard Wiedemann 2013-06-30 20:00:08 UTC
This is an autogenerated message for OBS integration:
This bug (825876) was mentioned in
https://build.opensuse.org/request/show/181531 Maintenance /
Comment 13 Bernhard Wiedemann 2013-07-01 08:00:37 UTC
This is an autogenerated message for OBS integration:
This bug (825876) was mentioned in
https://build.opensuse.org/request/show/181562 Evergreen:11.2 / python-bugzilla
Comment 14 Swamp Workflow Management 2013-07-06 08:05:14 UTC
openSUSE-SU-2013:1154-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 825876
CVE References: CVE-2013-2191
Sources used:
openSUSE 12.3 (src):    python-bugzilla-0.6.2-8.4.1
openSUSE 12.2 (src):    python-bugzilla-0.6.2-6.4.1
Comment 15 Swamp Workflow Management 2013-07-06 09:04:21 UTC
openSUSE-SU-2013:1155-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 825876
CVE References: CVE-2013-2191
Sources used:
openSUSE 11.4 (src):    python-bugzilla-0.6.2-13.1
Comment 16 Marcus Meissner 2013-07-08 12:21:39 UTC
no sle versions, so all done.
Comment 17 Bernhard Wiedemann 2013-07-11 06:00:49 UTC
This is an autogenerated message for OBS integration:
This bug (825876) was mentioned in
https://build.opensuse.org/request/show/182786 Evergreen:11.2 / python-bugzilla