Bug 853039 (CVE-2013-4566) - VUL-0: CVE-2013-4566: apache2-mod_nss: client certificate verification problematic
Summary: VUL-0: CVE-2013-4566: apache2-mod_nss: client certificate verification proble...
Status: RESOLVED FIXED
Alias: CVE-2013-4566
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2013-12-17
Assignee: Roman Drahtmueller
QA Contact: Security Team bot
URL:
Whiteboard: maint:released:sle11-sp1:55315 maint:...
Keywords:
Depends on:
Blocks:
 
Reported: 2013-11-30 09:38 UTC by Marcus Meissner
Modified: 2016-09-21 02:46 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
mod_nss-CVE-2013-4566.patch (651 bytes, patch)
2013-11-30 09:39 UTC, Marcus Meissner
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2013-11-30 09:38:14 UTC
embargoed, CRD Dec 3, between 1500 and 2000 utc

Albert Smith of OUSD(AT&L) reported this problem to Redhat.

CVE-2013-4566

The flaw is in the NSSVerifyClient (which is equivalent to mod_ssl's
SSLVerifyClient) setting enforcement.  If 'NSSVerifyClient none' is set
in the server / vhost context (i.e. when server is configured to not
request or require client certificate authentication on the initial
connection), and client certificate authentication is expected to be
required for a specific directory via 'NSSVerifyClient require'
setting, mod_nss fails to properly require certificate authentication.
Remote attacker can use this to access content of the restricted
directories.

Patch attached.

-- 
Tomas Hoger / Red Hat Security Response Team
Comment 1 Marcus Meissner 2013-11-30 09:39:06 UTC
Created attachment 569721 [details]
mod_nss-CVE-2013-4566.patch

attached patch
Comment 2 Swamp Workflow Management 2013-11-30 23:00:17 UTC
bugbot adjusting priority
Comment 3 Roman Drahtmueller 2013-12-02 12:47:19 UTC
package submitted against SUSE:SLE-11-SP1:Update:Test, request id 29744.
Comment 6 Swamp Workflow Management 2013-12-03 12:30:19 UTC
The SWAMPID for this issue is 55314.
This issue was rated as moderate.
Please submit fixed packages until 2013-12-17.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 7 Marcus Meissner 2013-12-06 14:15:11 UTC
is public now
Comment 8 Bernhard Wiedemann 2013-12-17 12:00:20 UTC
This is an autogenerated message for OBS integration:
This bug (853039) was mentioned in
https://build.opensuse.org/request/show/211193 13.1 / apache2-mod_nss
Comment 9 Swamp Workflow Management 2013-12-20 14:04:25 UTC
Update released for: apache2-mod_nss, apache2-mod_nss-debuginfo, apache2-mod_nss-debugsource
Products:
SLE-SERVER 11-SP1-TERADATA (x86_64)
Comment 10 Swamp Workflow Management 2013-12-20 16:48:15 UTC
Update released for: apache2-mod_nss, apache2-mod_nss-debuginfo, apache2-mod_nss-debugsource
Products:
SLE-DEBUGINFO 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLES4VMWARE 11-SP3 (i386, x86_64)
Comment 11 Swamp Workflow Management 2013-12-20 17:46:36 UTC
Update released for: apache2-mod_nss, apache2-mod_nss-debuginfo, apache2-mod_nss-debugsource
Products:
SLE-DEBUGINFO 11-SP2 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP2 (i386, ia64, ppc64, s390x, x86_64)
SLES4VMWARE 11-SP2 (i386, x86_64)
Comment 12 Swamp Workflow Management 2013-12-20 21:04:22 UTC
SUSE-SU-2013:1926-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 853039
CVE References: CVE-2013-4566
Sources used:
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    apache2-mod_nss-1.0.8-0.4.7.1
SUSE Linux Enterprise Server 11 SP3 (src):    apache2-mod_nss-1.0.8-0.4.7.1
SUSE Linux Enterprise Server 11 SP2 for VMware (src):    apache2-mod_nss-1.0.8-0.4.7.1
SUSE Linux Enterprise Server 11 SP2 (src):    apache2-mod_nss-1.0.8-0.4.7.1
Comment 13 Swamp Workflow Management 2013-12-25 17:09:04 UTC
openSUSE-SU-2013:1956-1: An update that solves one vulnerability and has one errata is now available.

Category: security (moderate)
Bug References: 847216,853039
CVE References: CVE-2013-4566
Sources used:
openSUSE 13.1 (src):    apache2-mod_nss-1.0.8-0.4.6.4.1
Comment 14 Marcus Meissner 2014-01-08 13:09:43 UTC
done
Comment 15 Bernhard Wiedemann 2014-02-20 22:00:19 UTC
This is an autogenerated message for OBS integration:
This bug (853039) was mentioned in
https://build.opensuse.org/request/show/223307 Factory / apache2-mod_nss
Comment 16 gm chen 2016-09-21 02:46:15 UTC
The SLES-11-SP1 was affected by this CVE? 
I need a submission for huawei costomer.