CVE Vulnerabilities

CVE-2017-2623

Improper Certificate Validation

Published: Jul 27, 2018 | Modified: Oct 09, 2019
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Ubuntu

It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as expected. This issue is partially mitigated on RHEL Atomic Host, where certificate pinning is used by default.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Rpm-ostree Rpm-ostree * 2017.3 (excluding)
Rpm-ostree-client Rpm-ostree * 2017.3 (excluding)
Red Hat Enterprise Linux Atomic Host 7 RedHat rpm-ostree-0:2017.1-5.atomic.el7 *
Red Hat Enterprise Linux Atomic Host 7 RedHat rpm-ostree-client-0:2017.1-6.atomic.el7 *

Potential Mitigations

References