FreeS/WAN X.509 Patch Certificate Verification Vulnerability
BID:10611
Info
FreeS/WAN X.509 Patch Certificate Verification Vulnerability
| Bugtraq ID: | 10611 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-0590 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 25 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Discovery of this vulnerability is credited to Thomas Walpuski <[email protected]>. |
| Vulnerable: |
Super FreeS/WAN Super FreeS/WAN 1.99.7 .3 strongSwan strongSwan 2.1.3 Openswan Openswan 2.1.2 Openswan Openswan 2.1.1 Openswan Openswan 1.0.5 Openswan Openswan 1.0.4 Gentoo Linux 1.4 _rc3 Gentoo Linux 1.4 _rc2 Gentoo Linux 1.4 _rc1 Gentoo Linux 1.4 FreeS/WAN FreeS/WAN 2.4 -r1 FreeS/WAN FreeS/WAN 1.9.6 FreeS/WAN FreeS/WAN 1.9.5 FreeS/WAN FreeS/WAN 1.9.4 FreeS/WAN FreeS/WAN 1.9.3 FreeS/WAN FreeS/WAN 1.9.2 FreeS/WAN FreeS/WAN 1.9.1 FreeS/WAN FreeS/WAN 1.9 Andreas Steffen x509 patch 1.5.5 Andreas Steffen x509 patch 1.5.4 Andreas Steffen x509 patch 0.9.39 |
| Not Vulnerable: |
Andreas Steffen x509 patch 1.6.1 Andreas Steffen x509 patch 0.9.41 |
Discussion
FreeS/WAN X.509 Patch Certificate Verification Vulnerability
FreeS/WAN X.509 patch is reported susceptible to a certificate verification vulnerability.
When the vulnerable implementation is negotiating an IPSec connection using PKCS#7 wrapped X.509 certificates, it can be fooled into authenticating fake certificates.
If an attacker crafts a Certificate Authority (CA) certificate and a user certificate with identical subjects, they can reportedly be improperly authenticated by FreeS/WAN.
Using this vulnerability, an attacker could potentially successfully authenticate to a FreeS/WAN VPN server. Further attacks on machines now accessible to the attacker are likely possible.
**Update: This vulnerability was previously thought to exist in the FreeS/WAN application, however, new information suggests that the issue is present in the X.509 patch for the application.
FreeS/WAN X.509 patch is reported susceptible to a certificate verification vulnerability.
When the vulnerable implementation is negotiating an IPSec connection using PKCS#7 wrapped X.509 certificates, it can be fooled into authenticating fake certificates.
If an attacker crafts a Certificate Authority (CA) certificate and a user certificate with identical subjects, they can reportedly be improperly authenticated by FreeS/WAN.
Using this vulnerability, an attacker could potentially successfully authenticate to a FreeS/WAN VPN server. Further attacks on machines now accessible to the attacker are likely possible.
**Update: This vulnerability was previously thought to exist in the FreeS/WAN application, however, new information suggests that the issue is present in the X.509 patch for the application.
Exploit / POC
FreeS/WAN X.509 Patch Certificate Verification Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
FreeS/WAN X.509 Patch Certificate Verification Vulnerability
Solution:
Gentoo has released advisory GLSA 200406-20 to address this issue. Gentoo have advised the following:
All FreeS/WAN 1.9x users should upgrade to the latest stable version:
# emerge sync
# emerge -pv "=net-misc/freeswan-1.99-r1"
# emerge "=net-misc/freeswan-1.99-r1"
All FreeS/WAN 2.x users should upgrade to the latest stable version:
# emerge sync
# emerge -pv ">=net-misc/freeswan-2.04-r1"
# emerge ">=net-misc/freeswan-2.04-r1"
All Openswan 1.x users should upgrade to the latest stable version:
# emerge sync
# emerge -pv "=net-misc/openswan-1.0.6_rc1"
# emerge "=net-misc/openswan-1.0.6_rc1"
All Openswan 2.x users should upgrade to the latest stable version:
# emerge sync
# emerge -pv ">=net-misc/openswan-2.1.4"
# emerge ">=net-misc/openswan-2.1.4"
All strongSwan users should upgrade to the latest stable version:
# emerge sync
# emerge -pv ">=net-misc/strongswan-2.1.3"
# emerge ">=net-misc/strongswan-2.1.3"
All Super-FreeS/WAN users should migrate to the latest stable version
of Openswan. Note that Portage will force a move for Super-FreeS/WAN
users to Openswan:
# emerge sync
# emerge -pv "=net-misc/openswan-1.0.6_rc1"
# emerge "=net-misc/openswan-1.0.6_rc1"
Mandrake has released an advisory (MDKSA-2004:070) to address this issue. Please see the referenced advisory for more information.
Solution:
Gentoo has released advisory GLSA 200406-20 to address this issue. Gentoo have advised the following:
All FreeS/WAN 1.9x users should upgrade to the latest stable version:
# emerge sync
# emerge -pv "=net-misc/freeswan-1.99-r1"
# emerge "=net-misc/freeswan-1.99-r1"
All FreeS/WAN 2.x users should upgrade to the latest stable version:
# emerge sync
# emerge -pv ">=net-misc/freeswan-2.04-r1"
# emerge ">=net-misc/freeswan-2.04-r1"
All Openswan 1.x users should upgrade to the latest stable version:
# emerge sync
# emerge -pv "=net-misc/openswan-1.0.6_rc1"
# emerge "=net-misc/openswan-1.0.6_rc1"
All Openswan 2.x users should upgrade to the latest stable version:
# emerge sync
# emerge -pv ">=net-misc/openswan-2.1.4"
# emerge ">=net-misc/openswan-2.1.4"
All strongSwan users should upgrade to the latest stable version:
# emerge sync
# emerge -pv ">=net-misc/strongswan-2.1.3"
# emerge ">=net-misc/strongswan-2.1.3"
All Super-FreeS/WAN users should migrate to the latest stable version
of Openswan. Note that Portage will force a move for Super-FreeS/WAN
users to Openswan:
# emerge sync
# emerge -pv "=net-misc/openswan-1.0.6_rc1"
# emerge "=net-misc/openswan-1.0.6_rc1"
Mandrake has released an advisory (MDKSA-2004:070) to address this issue. Please see the referenced advisory for more information.
References
FreeS/WAN X.509 Patch Certificate Verification Vulnerability
References:
References:
- [strongSwan] potential authentication bug in strongSwan/Openswan (Thomas Walpuski
) - [strongSwan] potential authentication bug in strongSwan/Openswan (Andreas Steffen
) - FreeS/WAN Homepage (FreeS/WAN)
- Openswan Homepage (Openswan)
- strongSwan Homepage (strongSwan)
- X.509 Certificate Support for the Linux FreeS/WAN IPsec Stack (Andreas Steffen)