CVE-2009-2417
lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
02 / AFFECTED SOFTWARE
Affected packages
66 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
SSL and TLS Server certificates contain one or more fields with server name or otherwise matching patterns. These strings are stored as content and length within the certificate, and thus there is no particular terminating character. curl's OpenSSL interfacing code did faulty assumptions about those names and patterns being null-terminated, allowing itself to be fooled in case a certificate would get a zero byte embedded into one of the name fields. To illustrate, a name that would show this vulnerability could look like: "example.com\0.haxx.se" This cert is thus made for "haxx.se" but curl would erroneously verify it with no complaints for "example.com". According to a recently published presentation, this kind of zero embedding has been proven to be possible with at least one CA.
lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
05 / REFERENCES
Further evidence
- http://curl.haxx.se/CVE-2009-2417/curl-7.10.6-CVE-2009-2417.patch
- http://curl.haxx.se/CVE-2009-2417/curl-7.11.0-CVE-2009-2417.patch
- http://curl.haxx.se/CVE-2009-2417/curl-7.12.1-CVE-2009-2417.patch
- http://curl.haxx.se/CVE-2009-2417/curl-7.15.1-CVE-2009-2417.patch
- http://curl.haxx.se/CVE-2009-2417/curl-7.15.5-CVE-2009-2417.patch
- http://curl.haxx.se/CVE-2009-2417/curl-7.16.4-CVE-2009-2417.patch
- http://curl.haxx.se/CVE-2009-2417/curl-7.18.1-CVE-2009-2417.patch
- http://curl.haxx.se/CVE-2009-2417/curl-7.19.0-CVE-2009-2417.patch
- http://curl.haxx.se/CVE-2009-2417/curl-7.19.5-CVE-2009-2417.patch
- http://curl.haxx.se/docs/adv_20090812.txt
- http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html
- http://secunia.com/advisories/36238
- http://secunia.com/advisories/36475
- http://secunia.com/advisories/37471
- http://secunia.com/advisories/45047
- http://shibboleth.internet2.edu/secadv/secadv_20090817.txt
- http://support.apple.com/kb/HT4077
- http://wiki.rpath.com/Advisories:rPSA-2009-0124
- http://www.securityfocus.com/archive/1/506055/100/0/threaded
- http://www.securityfocus.com/archive/1/507985/100/0/threaded
- http://www.securityfocus.com/bid/36032
- http://www.ubuntu.com/usn/USN-1158-1
- http://www.vmware.com/security/advisories/VMSA-2009-0016.html
- http://www.vupen.com/english/advisories/2009/2263
- http://www.vupen.com/english/advisories/2009/3316
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52405
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10114
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8542