[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: GnuTLS CVE-2009-2730 Patches (Was Re: GnuTLS 2.8.2)
From: |
Jamie Strandboge |
Subject: |
Re: GnuTLS CVE-2009-2730 Patches (Was Re: GnuTLS 2.8.2) |
Date: |
Mon, 17 Aug 2009 18:29:45 -0500 |
User-agent: |
Mutt/1.5.20 (2009-06-14) |
On Fri, 14 Aug 2009, Jamie Strandboge wrote:
> 1.2.9 does not pass the CN test yet, though
> at first glance certtool output looks comparable to the others.
1.2.9 also needed:
http://git.savannah.gnu.org/cgit/gnutls.git/patch/?id=7b80620f99f4d43f5eda692eefc5c969bb4263c0
Attached is an updated patch for 1.2.9 (still only lightly tested, but
verified to pass the test program). This and the 2.0.4 patch previously
posted now behave the same, but different from 2.4 and higher.
Specifically, when using:
$ certtool -i --infile /tmp/badguy-nul-cn.crt
We have:
|<1>| Found OID: '2.5.4.3' with value
'13187777772e62616e6b2e636f6d002e6261646775792e636f6d'
X.509 Certificate Information:
Version: 3
Serial Number (hex): 01
Issuer: C=GB,ST=Berkshire,L=Newbury,O=My Company
Ltd,OU=CA,CN=NULL-friendly CA
Validity:
Not Before: Tue Aug 4 07:33:43 UTC 2009
Not After: Fri Aug 2 07:33:43 UTC 2019
error: get_dn: ASN1 parser: Error in DER parsing.
...
This is in contrast to 2.4 and higher which has:
X.509 Certificate Information:
Version: 3
Serial Number (hex): 01
Issuer: C=GB,ST=Berkshire,L=Newbury,O=My Company
Ltd,OU=CA,CN=NULL-friendly CA
Validity:
Not Before: Tue Aug 04 07:33:43 UTC 2009
Not After: Fri Aug 02 07:33:43 UTC 2019
Subject: CN=#13187777772e62616e6b2e636f6d002e6261646775792e636f6
...
Jamie
--
Jamie Strandboge | http://www.canonical.com
CVE-2009-2730_1.2.9.patch
Description: Text Data
signature.asc
Description: Digital signature
- Re: GnuTLS 2.8.2, (continued)
- Re: GnuTLS 2.8.2, Jeff Cai, 2009/08/12
- Re: GnuTLS 2.8.2, Simon Josefsson, 2009/08/13
- Re: GnuTLS 2.8.2, Jeff Cai, 2009/08/14
- Re: GnuTLS 2.8.2, Simon Josefsson, 2009/08/14
- GnuTLS CVE-2009-2730 Patches (Was Re: GnuTLS 2.8.2), Jamie Strandboge, 2009/08/15
- Re: GnuTLS CVE-2009-2730 Patches, Simon Josefsson, 2009/08/15
- Re: GnuTLS CVE-2009-2730 Patches, Jamie Strandboge, 2009/08/17
- Re: GnuTLS CVE-2009-2730 Patches, Simon Josefsson, 2009/08/18
- Message not available
- Re: GnuTLS CVE-2009-2730 Patches, Simon Josefsson, 2009/08/20
- Re: GnuTLS CVE-2009-2730 Patches, Simon Josefsson, 2009/08/20
- Re: GnuTLS CVE-2009-2730 Patches (Was Re: GnuTLS 2.8.2),
Jamie Strandboge <=