Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20121011154355.GC2676@redhat.com>
Date: Thu, 11 Oct 2012 09:43:55 -0600
From: Vincent Danen <vdanen@...hat.com>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request: sSMTP doesn't validate server
 certificates

* [2012-10-10 11:59:13 +0200] Laurent Bigonville wrote:

>Hi,
>
>It seems that sSMTP is not checking the server certificate when
>connecting. This is quite annoying as one of the main ssmtp purpose is
>to be used on satellite systems that could be connected to untrusted
>networks.
>
>This has been reported (with a proposed patch) to the Debian BTS (see
>[0])
>
>Could you please allocate a CVE number for this?
>
>Cheers
>
>Laurent Bigonville
>
>[0] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=662960

I'm not sure it deserves one.

If you look at the TLS file in the source tarball, it indicates that
checking server certificates is not implemented and is something to add
in the future:

TODO:
* Check server certificate for changes and notify about it.
* Diffrent Certificate and Key file?

Since sSMTP clearly indicates that this feature is missing and
unsupported, then it was designed to _not_ do certificate checking.
Regardless of how good or bad that is, it was a design choice (to leave
it for a later date), and it's also clearly documented.

To me, that doesn't seem like a security flaw (as in sSMTP was designed
to check certificates and didn't or didn't do a good job of it).

-- 
Vincent Danen / Red Hat Security Response Team 

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.