Improper Certificate Validation in Apache Qpid Proton - CVE-2019-0223

 

Improper Certificate Validation in Apache Qpid Proton - CVE-2019-0223

Published: September 17, 2019


Vulnerability identifier: #VU21142
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0223
CWE-ID: CWE-295
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform man-in-the-middle attack.

The vulnerability exists due to Apache Qpid Proton (C library and its language bindings) allows anonymous TLS connections to with the peer, even when configured to verify the peer certificate. A remote attacker with ability to intercept and decrypt TLS traffic and perform MitM attack.


Affected software

Apache Qpid Proton
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Micro
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power
SUSE Package Hub 15
openSUSE Leap
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
Red Hat Satellite
Red Hat OpenStack for IBM Power
Red Hat OpenStack
python3-python-qpid-proton
qpid-proton-debugsource
python3-python-qpid-proton-debuginfo
qpid-proton-devel
qpid-proton-debuginfo
qpid-proton-devel-doc

How to mitigate CVE-2019-0223

Install updates from vendor's website.

Apache Qpid Proton - update to 0.28.0
python3-python-qpid-proton - update to 0.38.0-150000.6.3.1
qpid-proton-debugsource - update to 0.38.0-150000.6.3.1
python3-python-qpid-proton-debuginfo - update to 0.38.0-150000.6.3.1
qpid-proton-devel - update to 0.38.0-150000.6.3.1
qpid-proton-debuginfo - update to 0.38.0-150000.6.3.1
qpid-proton-devel-doc - update to 0.38.0-150000.6.3.1

External References

Related Security Bulletins