PT-2018-5976 · Apache+2 · Apache Tomcat Native Connector+2

Jonas Klempel

·

Publicado

2018-01-31

·

Atualizado

2019-04-09

·

CVE-2017-15698

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Apache Tomcat Native Connector versions 1.1.23 through 1.1.34 Apache Tomcat Native Connector versions 1.2.0 through 1.2.14
Description: The issue arises when parsing the AIA-Extension field of a client certificate. If the field is longer than 127 bytes, it is not handled correctly, resulting in the skipping of the OCSP check. This allows client certificates that should be rejected to be accepted, provided that OCSP checks are in use.
Recommendations: For Apache Tomcat Native Connector versions 1.1.23 through 1.1.34, update to a version that correctly handles the AIA-Extension field. For Apache Tomcat Native Connector versions 1.2.0 through 1.2.14, update to a version that correctly handles the AIA-Extension field. As a temporary workaround, consider disabling the use of client certificates that rely on OCSP checks until a patch is available.

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1680
CVE-2017-15698
DLA-1276-1
DSA-4118-1
MGASA-2018-0150
RHSA-2018:0466
SUSE-SU-2019:14014-1
SUSE-SU-2019_14014-1

Produtos afetados

Alt Linux
Apache Tomcat Native Connector
Suse