Improper Certificate Validation in Apache Qpid Proton - CVE-2019-0223
Published: September 17, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform man-in-the-middle attack.
The vulnerability exists due to Apache Qpid Proton (C library and its language bindings) allows anonymous TLS connections to with the peer, even when configured to verify the peer certificate. A remote attacker with ability to intercept and decrypt TLS traffic and perform MitM attack.
Affected software
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Micro
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power
SUSE Package Hub 15
openSUSE Leap
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
Red Hat Satellite
Red Hat OpenStack for IBM Power
Red Hat OpenStack
python3-python-qpid-proton
qpid-proton-debugsource
python3-python-qpid-proton-debuginfo
qpid-proton-devel
qpid-proton-debuginfo
qpid-proton-devel-doc
How to mitigate CVE-2019-0223
python3-python-qpid-proton - update to 0.38.0-150000.6.3.1
qpid-proton-debugsource - update to 0.38.0-150000.6.3.1
python3-python-qpid-proton-debuginfo - update to 0.38.0-150000.6.3.1
qpid-proton-devel - update to 0.38.0-150000.6.3.1
qpid-proton-debuginfo - update to 0.38.0-150000.6.3.1
qpid-proton-devel-doc - update to 0.38.0-150000.6.3.1
External References
- http://www.openwall.com/lists/oss-security/2019/04/23/4
- http://www.securityfocus.com/bid/108044
- https://access.redhat.com/errata/RHSA-2019:0886
- https://access.redhat.com/errata/RHSA-2019:1398
- https://access.redhat.com/errata/RHSA-2019:1399
- https://access.redhat.com/errata/RHSA-2019:1400
- https://issues.apache.org/jira/browse/PROTON-2014?page=com.atlassian.jira.plugin.system.issuetabpanels%3Aall-tabpanel
- https://lists.apache.org/thread.html/008ee5e78e5a090e1fcc5f6617f425e4e51d59f03d3eda2dd006df9f@%3Cusers.qpid.apache.org%3E
- https://lists.apache.org/thread.html/3adb2f020f705b4fd453982992a68cd10f9d5ac728b699efdb73c1f5@%3Cdev.qpid.apache.org%3E
- https://lists.apache.org/thread.html/49c83f0acce5ceaeffca51714ec2ba0f0199bcb8f99167181bba441b@%3Cdev.qpid.apache.org%3E
- https://lists.apache.org/thread.html/914424e4d798a340f523b6169aaf39b626971d9bb00fcdeb1d5d6c0d@%3Ccommits.qpid.apache.org%3E
- https://lists.apache.org/thread.html/d9c9a882a292e2defaed1f954528c916fb64497ce57db652727e39b0@%3Cannounce.apache.org%3E
Related Security Bulletins
- MitM attack in Apache Qpid Proton
- Red Hat update for qpid-proton
- Red Hat update for qpid-proton
- Red Hat update for qpid-proton
- Red Hat update for qpid-proton
- Red Hat update for qpid-proton
- Red Hat update for qpid-proton
- Red Hat update for qpid-proton
- Red Hat update for qpid-proton
- Red Hat update for qpid-proton
- SUSE update for qpid-proton