Bug 1068685 (CVE-2017-16853)

Summary: VUL-0: CVE-2017-16853: opensaml: The DynamicMetadataProvider class fails to properly configure itself with the MetadataFilter plugins, allowing active attackers to MITM etc
Product: [Novell Products] SUSE Security Incidents Reporter: Johannes Segitz <jsegitz>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Major    
Priority: P3 - Medium CC: astieger, kstreitova, smash_bz
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/195135/
Whiteboard: CVSSv2:SUSE:CVE-2017-16853:7.1:(AV:N/AC:H/Au:N/C:C/I:C/A:N) CVSSv3:SUSE:CVE-2017-16853:7.4:(AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N) CVSSv3:RedHat:CVE-2017-16853:6.5:(AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Johannes Segitz 2017-11-17 12:20:16 UTC
CVE-2017-16853

The DynamicMetadataProvider class in
saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML
before 2.6.1 fails to properly configure itself with the MetadataFilter plugins
and does not perform critical security checks such as signature verification,
enforcement of validity periods, and other checks specific to deployments, aka
CPPOST-105.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-16853
http://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-16853.html
http://www.debian.org/security/2017/dsa-4039
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881856
https://git.shibboleth.net/view/?p=cpp-opensaml.git;a=commit;h=6182b0acf2df670e75423c2ed7afe6950ef11c9d
Comment 1 Kristyna Streitova 2017-11-21 12:22:17 UTC
Done.

|    Codestream    |   Request    |
|------------------|--------------|
| SLE12SP1         | #146768      |
| openSUSE:Leap    | via SLE12SP1 |
| openSUSE:Factory | #544152      |

I'm reassigning it back to the security-team.
Comment 3 Swamp Workflow Management 2017-12-07 20:12:14 UTC
SUSE-SU-2017:3234-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1068685
CVE References: CVE-2017-16853
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP3 (src):    opensaml-2.5.5-3.3.1
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    opensaml-2.5.5-3.3.1
SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src):    opensaml-2.5.5-3.3.1
SUSE Linux Enterprise Server 12-SP3 (src):    opensaml-2.5.5-3.3.1
SUSE Linux Enterprise Server 12-SP2 (src):    opensaml-2.5.5-3.3.1
Comment 4 Andreas Stieger 2017-12-08 07:30:32 UTC
done
Comment 5 Swamp Workflow Management 2017-12-08 11:12:43 UTC
openSUSE-SU-2017:3241-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1068685
CVE References: CVE-2017-16853
Sources used:
openSUSE Leap 42.3 (src):    opensaml-2.5.5-6.1
openSUSE Leap 42.2 (src):    opensaml-2.5.5-3.3.1