LWN.net Logo

libksba: parsing failure

Package(s):libksba CVE #(s):CVE-2006-5111
Created:October 17, 2006 Updated:October 18, 2006
Description: A parsing failure was discovered in the handling of X.509 certificates that contained extra trailing data. Malformed or malicious certificates could cause services using libksba to crash, potentially creating a denial of service.
Alerts:
Mandriva MDKSA-2006:183 2006-10-17
Ubuntu USN-365-1 2006-10-16

(Log in to post comments)

libksba: parsing failure

Posted Oct 19, 2006 8:24 UTC (Thu) by dd9jn (subscriber, #4459) [Link]

As author of libksba (clearly stated with a security address in AUTHORS), I have not been contacted. Ubuntu seems to have fixed this in a version 0.9.9 whereas other distributions talk about 0.9.15 not affected but anyway fixed! Others even claim that 1.0 is affected.

According to my records the last such bug has been fixed with 0.9.10 back in December 2004. So the Ubuntu fix looks plausible.

However, I have no idea whether this is actually what the CVE talks about.
Looking at the Suse update, they include a patch for 0.9.12 which fixes a parsing problem with some certificates as well as a one liner to fix a possible NULL dereference. That fix definitely does not fix any exploitable bug as indicated in the CVE. According to their changelog it fixes bug 177462. I have found no way to access the Suse bug tracker to look it up.

Issuing a CVE candidate without contacting the author is IMHO somewhat unprofessional. Is there still something lurking in 1.0.0?

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds