{"thread":{"id":"32995","subject":"Certificate validation vulnerability in Git","startedAt":"2013-02-24T17:31:50Z","lastAt":"2013-02-25T15:42:42Z","messageCount":7,"participants":["Zubin Mithra","Andreas Ericsson","Jeff King","Junio C Hamano"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"210187","messageId":"CAA5xPpmmZuMK7q3-pTOx4L6DxFtyw5HWYdH7kHEsK=96KM5kAQ@mail.gmail.com","threadId":"32995","inReplyTo":null,"subject":"Certificate validation vulnerability in Git","fromName":"Zubin Mithra","fromEmail":"zubin.mithra@gmail.com","sentAt":"2013-02-24T17:31:50Z","receivedAt":"2013-02-24T17:31:50Z","isPatch":false,"sender":{"key":"zubin.mithra@gmail.com","avatar":null},"body":"Hello,\n\nThere seems to be a security issue in the way git uses openssl for\ncertificate validation. Similar occurrences have been found and\ndocumented in other open source projects, the research can be found at\n[1].\n\n-=========]\n- imap-send.c\n\nLine 307\n\n 307   ret = SSL_connect(sock->ssl);\n 308   if (ret <= 0) {\n 309     socket_perror(\"SSL_connect\", sock, ret);\n 310     return -1;\n 311   }\n 312\n\nCertificate validation errors are signaled either through return\nvalues of SSL_connect or by setting internal flags. The internal flags\nneed to be checked using the SSL_get_verify_result function. This is\nnot performed.\n\nKindly fix these issues, file a CVE and credit it to Dhanesh K. and\nZubin Mithra. Thanks.\n\nWe are not subscribed to this list, so we'd appreciate it if you could\nCC us in the replies.\n\nHope this helps.\n\nThanks!\nZubin\n\n[1] http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf\n"},{"id":"210190","messageId":"512A601B.80807@op5.se","threadId":"32995","inReplyTo":"CAA5xPpmmZuMK7q3-pTOx4L6DxFtyw5HWYdH7kHEsK=96KM5kAQ@mail.gmail.com","subject":"Re: Certificate validation vulnerability in Git","fromName":"Andreas Ericsson","fromEmail":"ae@op5.se","sentAt":"2013-02-24T18:46:51Z","receivedAt":"2013-02-24T18:46:51Z","isPatch":false,"sender":{"key":"ae@op5.se","avatar":"https://gravatar.com/avatar/426e89595c75a8f5252dd0c989e5fabe5bcac616e68557427ad9aef6b0ca342a?d=mp&s=160"},"body":"On 02/24/2013 06:31 PM, Zubin Mithra wrote:\n> Hello,\n> \n> There seems to be a security issue in the way git uses openssl for\n> certificate validation. Similar occurrences have been found and\n> documented in other open source projects, the research can be found at\n> [1].\n> \n> -=========]\n> - imap-send.c\n> \n> Line 307\n> \n>   307   ret = SSL_connect(sock->ssl);\n>   308   if (ret <= 0) {\n>   309     socket_perror(\"SSL_connect\", sock, ret);\n>   310     return -1;\n>   311   }\n>   312\n> \n> Certificate validation errors are signaled either through return\n> values of SSL_connect or by setting internal flags. The internal flags\n> need to be checked using the SSL_get_verify_result function. This is\n> not performed.\n> \n> Kindly fix these issues, file a CVE and credit it to Dhanesh K. and\n> Zubin Mithra. Thanks.\n> \n\nThe lack of certificate authority verification presents no attack vector\nfor git imap-send. As such, it doesn't warrant a CVE. I'm sure you'll\nbe credited with a \"reported-by\" line in the commit message if someone\ndecides to fix it though. Personally, I'm not fussed.\n\n> We are not subscribed to this list, so we'd appreciate it if you could\n> CC us in the replies.\n> \n\nThat's standard on this list. Please follow the same convention if/when\nyou reply. Thanks.\n\n-- \nAndreas Ericsson                   andreas.ericsson@op5.se\nOP5 AB                             www.op5.se\nTel: +46 8-230225                  Fax: +46 8-230231\n\nConsidering the successes of the wars on alcohol, poverty, drugs and\nterror, I think we should give some serious thought to declaring war\non peace.\n"},{"id":"210213","messageId":"CAA5xPpm=5NP=uDkEWBSosOE=0Jp1MBD5qG7sHKxCUsv6iZ59tg@mail.gmail.com","threadId":"32995","inReplyTo":"512A601B.80807@op5.se","subject":"Re: Certificate validation vulnerability in Git","fromName":"Zubin Mithra","fromEmail":"zubin.mithra@gmail.com","sentAt":"2013-02-25T02:28:11Z","receivedAt":"2013-02-25T02:28:11Z","isPatch":false,"sender":{"key":"zubin.mithra@gmail.com","avatar":null},"body":"Hello,\n\nOn Mon, Feb 25, 2013 at 12:16 AM, Andreas Ericsson <ae@op5.se> wrote:\n> On 02/24/2013 06:31 PM, Zubin Mithra wrote:\n>> Hello,\n>>\n>> There seems to be a security issue in the way git uses openssl for\n>> certificate validation. Similar occurrences have been found and\n>> documented in other open source projects, the research can be found at\n>> [1].\n>>\n>> -=========]\n>> - imap-send.c\n>>\n>> Line 307\n>>\n>>   307   ret = SSL_connect(sock->ssl);\n>>   308   if (ret <= 0) {\n>>   309     socket_perror(\"SSL_connect\", sock, ret);\n>>   310     return -1;\n>>   311   }\n>>   312\n>>\n>> Certificate validation errors are signaled either through return\n>> values of SSL_connect or by setting internal flags. The internal flags\n>> need to be checked using the SSL_get_verify_result function. This is\n>> not performed.\n>>\n>> Kindly fix these issues, file a CVE and credit it to Dhanesh K. and\n>> Zubin Mithra. Thanks.\n>>\n>\n> The lack of certificate authority verification presents no attack vector\n> for git imap-send. As such, it doesn't warrant a CVE. I'm sure you'll\n> be credited with a \"reported-by\" line in the commit message if someone\n> decides to fix it though. Personally, I'm not fussed.\n\nI'd like to add in a few points -- generally SSL/TLS would be used in\ncases where the authenticity of the server and confidentiality of the\nmessages transferred would be required. In this particular case, the\nthreat scenarios would be :-\n\n- Usage of an invalid attacker certificate could result in the\nattacker gaining access to authentication information sent over the\nwire.\n- If the code repository were private, the patches thus generated are\nalso assumed to be kept private. An invalid certificate check at the\nclient side would enable an attacker to gain access to those patches.\n\n\nIs there anything I'm missing? I believe this is a valid security issue.\n\n\n\nThanks,\nZubin\n\n\n>\n>> We are not subscribed to this list, so we'd appreciate it if you could\n>> CC us in the replies.\n>>\n>\n> That's standard on this list. Please follow the same convention if/when\n> you reply. Thanks.\n>\n> --\n> Andreas Ericsson                   andreas.ericsson@op5.se\n> OP5 AB                             www.op5.se\n> Tel: +46 8-230225                  Fax: +46 8-230231\n>\n> Considering the successes of the wars on alcohol, poverty, drugs and\n> terror, I think we should give some serious thought to declaring war\n> on peace.\n"},{"id":"210214","messageId":"20130225031648.GA31988@sigill.intra.peff.net","threadId":"32995","inReplyTo":"CAA5xPpmmZuMK7q3-pTOx4L6DxFtyw5HWYdH7kHEsK=96KM5kAQ@mail.gmail.com","subject":"Re: Certificate validation vulnerability in Git","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2013-02-25T03:16:48Z","receivedAt":"2013-02-25T03:16:48Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Sun, Feb 24, 2013 at 11:01:50PM +0530, Zubin Mithra wrote:\n\n> There seems to be a security issue in the way git uses openssl for\n> certificate validation. Similar occurrences have been found and\n> documented in other open source projects, the research can be found at\n> [1].\n> \n> -=========]\n> - imap-send.c\n> \n> Line 307\n> \n>  307   ret = SSL_connect(sock->ssl);\n>  308   if (ret <= 0) {\n>  309     socket_perror(\"SSL_connect\", sock, ret);\n>  310     return -1;\n>  311   }\n>  312\n> \n> Certificate validation errors are signaled either through return\n> values of SSL_connect or by setting internal flags. The internal flags\n> need to be checked using the SSL_get_verify_result function. This is\n> not performed.\n\nI'm not sure what you mean. We use SSL_CTX_set_verify to turn on peer\ncertificate verification, which will cause SSL_connect to return\nfailure if the certificate signature cannot be traced back to a CA cert\nfrom our local store.\n\nIs there some case where this does not happen properly? If so, can you\ngive an example? The paper you referenced says only that there are some\nspecial cases where SSL_connect does not notice the error, but then\ngives an example where the application does not turn on SSL_VERIFY_PEER.\nBut git does. Are there are other cases that SSL_VERIFY_PEER does not\nhandle?\n\nThere is a _different_ problem not handled by the code you show above,\nwhich is that SSL_connect does not verify that the hostname we connected\nto matches the signed certificate. But that was fixed already by b62fb07\n(imap-send: the subject of SSL certificate must match the host,\n2013-02-15), which is in git v1.8.1.4.\n\n-Peff\n"},{"id":"210215","messageId":"20130225031847.GB31988@sigill.intra.peff.net","threadId":"32995","inReplyTo":"512A601B.80807@op5.se","subject":"Re: Certificate validation vulnerability in Git","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2013-02-25T03:18:47Z","receivedAt":"2013-02-25T03:18:47Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Sun, Feb 24, 2013 at 07:46:51PM +0100, Andreas Ericsson wrote:\n\n> The lack of certificate authority verification presents no attack vector\n> for git imap-send. As such, it doesn't warrant a CVE. I'm sure you'll\n> be credited with a \"reported-by\" line in the commit message if someone\n> decides to fix it though. Personally, I'm not fussed.\n\nSure it presents an attack vector. I can man-in-the-middle your\nimap-send client and read your otherwise secret patches. Or your\notherwise secret imap password.\n\n-Peff\n"},{"id":"210221","messageId":"7v8v6d3qh8.fsf@alter.siamese.dyndns.org","threadId":"32995","inReplyTo":"20130225031847.GB31988@sigill.intra.peff.net","subject":"Re: Certificate validation vulnerability in Git","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2013-02-25T05:35:47Z","receivedAt":"2013-02-25T05:35:47Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Jeff King <peff@peff.net> writes:\n\n> On Sun, Feb 24, 2013 at 07:46:51PM +0100, Andreas Ericsson wrote:\n>\n>> The lack of certificate authority verification presents no attack vector\n>> for git imap-send. As such, it doesn't warrant a CVE. I'm sure you'll\n>> be credited with a \"reported-by\" line in the commit message if someone\n>> decides to fix it though. Personally, I'm not fussed.\n>\n> Sure it presents an attack vector. I can man-in-the-middle your\n> imap-send client and read your otherwise secret patches. Or your\n> otherwise secret imap password.\n\nYes, the lack of verification alone will not hurt the victim; you\nwould need to also be able to insert yourself in the middle, perhaps\nby poisoning the victim's DNS.  But one of the points of using\nSSL/TLS is to resist such an attack, and it certainly is an attack\nsurfce, even though it may be of a lessor kind than other kinds of\nattacks.\n"},{"id":"210249","messageId":"CAA5xPpmBWLRXs_SfwOAkps8fTeFUW3bEnrDQE_FXjXhmBbC4MA@mail.gmail.com","threadId":"32995","inReplyTo":"20130225031648.GA31988@sigill.intra.peff.net","subject":"Re: Certificate validation vulnerability in Git","fromName":"Zubin Mithra","fromEmail":"zubin.mithra@gmail.com","sentAt":"2013-02-25T15:42:42Z","receivedAt":"2013-02-25T15:42:42Z","isPatch":false,"sender":{"key":"zubin.mithra@gmail.com","avatar":null},"body":"On Mon, Feb 25, 2013 at 8:46 AM, Jeff King <peff@peff.net> wrote:\n> On Sun, Feb 24, 2013 at 11:01:50PM +0530, Zubin Mithra wrote:\n>\n>> There seems to be a security issue in the way git uses openssl for\n>> certificate validation. Similar occurrences have been found and\n>> documented in other open source projects, the research can be found at\n>> [1].\n>>\n>> -=========]\n>> - imap-send.c\n>>\n>> Line 307\n>>\n>>  307   ret = SSL_connect(sock->ssl);\n>>  308   if (ret <= 0) {\n>>  309     socket_perror(\"SSL_connect\", sock, ret);\n>>  310     return -1;\n>>  311   }\n>>  312\n>>\n>> Certificate validation errors are signaled either through return\n>> values of SSL_connect or by setting internal flags. The internal flags\n>> need to be checked using the SSL_get_verify_result function. This is\n>> not performed.\n>\n> I'm not sure what you mean. We use SSL_CTX_set_verify to turn on peer\n> certificate verification, which will cause SSL_connect to return\n> failure if the certificate signature cannot be traced back to a CA cert\n> from our local store.\n>\n> Is there some case where this does not happen properly? If so, can you\n> give an example? The paper you referenced says only that there are some\n> special cases where SSL_connect does not notice the error, but then\n> gives an example where the application does not turn on SSL_VERIFY_PEER.\n> But git does. Are there are other cases that SSL_VERIFY_PEER does not\n> handle?\n\nIndeed -- it appears that I was mistaken. I had a quick look at the\nopenssl source code and it does seem that SSL_VERIFY_PEER is\nequivalent to SSL_get_verify_result.\n\nThank you for your time!\n\n- Zubin\n\n>\n> There is a _different_ problem not handled by the code you show above,\n> which is that SSL_connect does not verify that the hostname we connected\n> to matches the signed certificate. But that was fixed already by b62fb07\n> (imap-send: the subject of SSL certificate must match the host,\n> 2013-02-15), which is in git v1.8.1.4.\n>\n> -Peff\n"}]}