REDHAT-BUG-2505982: High severity Netty Netty vulnerability
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, OcspClient does not validate that the CertificateID in an OCSP response matches the requested CertificateID, which can lead to replay attack. OcspClient.validateResponse accepts a legitimately signed GOOD status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.1.136.Final - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.2.16.Final
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2505982?
The severity of REDHAT-BUG-2505982 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2505982?
To fix REDHAT-BUG-2505982, update to Netty version 4.2.16.Final or later.
What is the impact of REDHAT-BUG-2505982?
The impact of REDHAT-BUG-2505982 is a potential certificate validation failure in OCSP responses.
Which versions are affected by REDHAT-BUG-2505982?
Versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final of Netty are affected.
What component does REDHAT-BUG-2505982 affect?
REDHAT-BUG-2505982 affects the OcspClient component of the Netty framework.