git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Certificate validation vulnerability in Git

From
ZMZubin Mithra <zubin.mithra@gmail.com>
Date
Feb 25, 2013, 02:28 UTC
Message-ID
<CAA5xPpm=5NP=uDkEWBSosOE=0Jp1MBD5qG7sHKxCUsv6iZ59tg@mail.gmail.com>
In-Reply-To
<512A601B.80807@op5.se>
Hello,
On Mon, Feb 25, 2013 at 12:16 AM, Andreas Ericsson <ae@op5.se> wrote:
Show 33 quoted lines
> On 02/24/2013 06:31 PM, Zubin Mithra wrote:
>> Hello,
>>
>> There seems to be a security issue in the way git uses openssl for
>> certificate validation. Similar occurrences have been found and
>> documented in other open source projects, the research can be found at
>> [1].
>>
>> -=========]
>> - imap-send.c
>>
>> Line 307
>>
>>   307   ret = SSL_connect(sock->ssl);
>>   308   if (ret <= 0) {
>>   309     socket_perror("SSL_connect", sock, ret);
>>   310     return -1;
>>   311   }
>>   312
>>
>> Certificate validation errors are signaled either through return
>> values of SSL_connect or by setting internal flags. The internal flags
>> need to be checked using the SSL_get_verify_result function. This is
>> not performed.
>>
>> Kindly fix these issues, file a CVE and credit it to Dhanesh K. and
>> Zubin Mithra. Thanks.
>>
>
> The lack of certificate authority verification presents no attack vector
> for git imap-send. As such, it doesn't warrant a CVE. I'm sure you'll
> be credited with a "reported-by" line in the commit message if someone
> decides to fix it though. Personally, I'm not fussed.

I'd like to add in a few points -- generally SSL/TLS would be used in cases where the authenticity of the server and confidentiality of the messages transferred would be required. In this particular case, the threat scenarios would be :-

- Usage of an invalid attacker certificate could result in the
attacker gaining access to authentication information sent over the
wire.
- If the code repository were private, the patches thus generated are
also assumed to be kept private. An invalid certificate check at the
client side would enable an attacker to gain access to those patches.
Is there anything I'm missing? I believe this is a valid security issue.

Thanks, Zubin

Show 16 quoted lines
>
>> We are not subscribed to this list, so we'd appreciate it if you could
>> CC us in the replies.
>>
>
> That's standard on this list. Please follow the same convention if/when
> you reply. Thanks.
>
> --
> Andreas Ericsson                   andreas.ericsson@op5.se
> OP5 AB                             www.op5.se
> Tel: +46 8-230225                  Fax: +46 8-230231
>
> Considering the successes of the wars on alcohol, poverty, drugs and
> terror, I think we should give some serious thought to declaring war
> on peace.
Previous: Andreas EricssonNext: Jeff King
Message 3 of 7 in “Certificate validation vulnerability in Git”
  1. Zubin MithraFeb 24, 2013
  2. Andreas EricssonFeb 24, 2013
  3. Zubin MithraFeb 25, 2013
  4. Jeff KingFeb 25, 2013
  5. Junio C HamanoFeb 25, 2013
  6. Jeff KingFeb 25, 2013
  7. Zubin MithraFeb 25, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.