Bug 1205509 - (CVE-2022-43705) VUL-0: CVE-2022-43705: Botan: OCSP response falsification
(CVE-2022-43705)
VUL-0: CVE-2022-43705: Botan: OCSP response falsification
Status: IN_PROGRESS
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Minor
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/348199/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-11-17 08:33 UTC by Carlos López
Modified: 2022-11-23 14:25 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carlos López 2022-11-17 08:33:56 UTC
rh#2143417

Botan 2.19.2 and older failed to verify that an authorized responder certificate embedded in an OCSP response is authorized by the issuing CA. As a result, any valid signature by an embedded certificate passed the check and was allowed to make claims about the revocation status of certificates of any CA.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=2143417
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-43705
Comment 1 Carlos López 2022-11-17 08:34:35 UTC
Relevant for:
- openSUSE:Backports:SLE-12:Update  1.10.9
- openSUSE:Backports:SLE-15-SP3     2.10.0
- openSUSE:Backports:SLE-15-SP4     2.18.2
- openSUSE:Backports:SLE-15-SP5     2.19.2
- openSUSE:Factory                  2.19.2
Comment 2 Jason Sikes 2022-11-17 21:20:08 UTC
Hi Carlos!

Is relevant for SUSE:SLE-12:Update in SLE?
Comment 3 Jason Sikes 2022-11-18 05:19:55 UTC
(In reply to Jason Sikes from comment #2)
> Hi Carlos!
> 
> Is relevant for SUSE:SLE-12:Update in SLE?

Is *this* relevant for SUSE:SLE-12:Update in SLE?

(sigh) I should proofread my stuff.
Comment 4 Carlos López 2022-11-18 08:37:11 UTC
(In reply to Jason Sikes from comment #3)
> (In reply to Jason Sikes from comment #2)
> > Hi Carlos!
> > 
> > Is relevant for SUSE:SLE-12:Update in SLE?
> 
> Is *this* relevant for SUSE:SLE-12:Update in SLE?
> 
> (sigh) I should proofread my stuff.

Right, I missed it:
https://smelt.suse.de/maintained/?q=Botan
Comment 6 Jason Sikes 2022-11-19 02:30:38 UTC
(In reply to Carlos López from comment #4)
> (In reply to Jason Sikes from comment #3)
> > (In reply to Jason Sikes from comment #2)
> > > Hi Carlos!
> > > 
> > > Is relevant for SUSE:SLE-12:Update in SLE?
> > 
> > Is *this* relevant for SUSE:SLE-12:Update in SLE?
> > 
> > (sigh) I should proofread my stuff.
> 
> Right, I missed it:
> https://smelt.suse.de/maintained/?q=Botan

Thank you!

And now that I have looked at it, I can see that OCSP support was added to Botan-1.11.0.

So SLE-12:Update and openSUSE:Backports:SLE-12:Update are not affected.
Comment 7 Jason Sikes 2022-11-19 03:07:12 UTC
I submitted updates to Botan-2.19.3 in Factory and Backports:SLE-15-SP5.

I also wrote patches for openSUSE:Backports:SLE-15-SP3 and openSUSE:Backports:SLE-15-SP4, but I'm waiting for one of my teammates to validate it. It's an unusual patch.
Comment 8 Jason Sikes 2022-11-21 20:00:50 UTC
Created submissions:

> | CODESTREAM                    | VERSION | SOLUTION          | STATUS                              |
> |-------------------------------+---------+-------------------+-------------------------------------|
> | SUSE:SLE-12:Update            |  1.10.9 |                   | Not Affected: OCSP was added 1.11.0 |
> | openSUSE:Backports:SLE-15-SP3 |  2.10.0 | Added two patches | created request id 1037178          |
> | openSUSE:Backports:SLE-15-SP4 |  2.18.2 | Added two patches | created request id 1037177          |
> | openSUSE:Backports:SLE-15-SP5 |  2.19.2 | Update to 2.19.3  | created request id 1036535          |
> | openSUSE:Factory              |  2.19.2 | Update to 2.19.3  | created request id 1036530          |

Assigning to Security-Team.
Comment 9 OBSbugzilla Bot 2022-11-21 21:35:03 UTC
This is an autogenerated message for OBS integration:
This bug (1205509) was mentioned in
https://build.opensuse.org/request/show/1037177 Backports:SLE-15-SP4 / Botan
https://build.opensuse.org/request/show/1037178 Backports:SLE-15-SP3 / Botan
Comment 10 Swamp Workflow Management 2022-11-23 14:21:41 UTC
openSUSE-SU-2022:10210-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1205509
CVE References: CVE-2022-43705
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP3 (src):    Botan-2.10.0-bp153.3.3.1
Comment 11 Swamp Workflow Management 2022-11-23 14:25:51 UTC
openSUSE-SU-2022:10211-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1205509
CVE References: CVE-2022-43705
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP4 (src):    Botan-2.18.2-bp154.2.3.1