CVE Vulnerabilities

CVE-2017-2623

Improper Certificate Validation

Published: Jul 27, 2018 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as expected. This issue is partially mitigated on RHEL Atomic Host, where certificate pinning is used by default.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
Rpm-ostreeRpm-ostree*2017.3 (excluding)
Rpm-ostree-clientRpm-ostree*2017.3 (excluding)
Red Hat Enterprise Linux Atomic Host 7RedHatrpm-ostree-0:2017.1-5.atomic.el7*
Red Hat Enterprise Linux Atomic Host 7RedHatrpm-ostree-client-0:2017.1-6.atomic.el7*

Potential Mitigations

References