REDHAT-BUG-1093273: Medium severity Ignite Realtime Smack XMPP API vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-0363 to the following vulnerability:
Name: CVE-2014-0363 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0363 Assigned: 20131205 Reference: http://community.igniterealtime.org/blogs/ignite/2014/04/17/asmack-400-rc1-has-been-released Reference: http://issues.igniterealtime.org/browse/SMACK-410 Reference: CERT-VN:VU#489228 Reference: http://www.kb.cert.org/vuls/id/489228
The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.
The man-in-the-middle attacker requires a certificate that is valid for any domain name.
Upstream patch: http://fisheye.igniterealtime.org/changelog/smackgit?cs=93030c218c62cf0a0a8ea48746db1452fa34033c
From code inspection, this issue affects the 3.2.2 version in Fedora (the CERT advisory mentions version 3.4.1 and possibly earlier versions).
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1093273?
The severity of REDHAT-BUG-1093273 is categorized based on the impact of the CVE-2014-0363 vulnerability, which can lead to potential security risks.
How do I fix REDHAT-BUG-1093273?
To fix REDHAT-BUG-1093273, you should update your Ignite Realtime Smack XMPP API to a version that is not affected, specifically versions 3.4.2 and above.
What systems are affected by REDHAT-BUG-1093273?
REDHAT-BUG-1093273 affects Ignite Realtime Smack XMPP API versions from 3.2.2 up to 4.0.0-rc1.
Is there a workaround for REDHAT-BUG-1093273?
There are no specific workarounds documented for REDHAT-BUG-1093273 apart from upgrading to a patched version.
What is the CVE identifier for the vulnerability described in REDHAT-BUG-1093273?
The CVE identifier for the vulnerability described in REDHAT-BUG-1093273 is CVE-2014-0363.