[Pkg-freeipa-devel] Bug#942463: jss: CVE-2019-14823

Salvatore Bonaccorso carnil at debian.org
Wed Oct 16 21:07:34 BST 2019


Source: jss
Version: 4.6.1-3
Severity: grave
Tags: security upstream
Forwarded: https://github.com/dogtagpki/jss/pull/284

Hi,

The following vulnerability was published for jss.

CVE-2019-14823[0]:
| A flaw was found in the "Leaf and Chain" OCSP policy implementation in
| JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it
| implicitly trusted the root certificate of a certificate chain.
| Applications using this policy may not properly verify the chain and
| could be vulnerable to attacks such as Man in the Middle.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-14823
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14823
[1] https://github.com/dogtagpki/jss/pull/284
[2] https://github.com/dogtagpki/jss/commit/be37ff4738b4696d529a13b6ed33c7ac56d97ba4

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



More information about the Pkg-freeipa-devel mailing list