potentially vulnerable to cve-2009-3555

Bug #566467 reported by Rune Philosof
286
This bug affects 4 people
Affects Status Importance Assigned to Milestone
Launchpad itself
Won't Fix
High
Robert Collins
Ubuntu Website - OBSOLETE
Won't Fix
Undecided
The Canonical Sysadmins
Ubuntu
Invalid
Undecided
Unassigned

Bug Description

Symptoms
========

Using firefox open http://wiki.ubuntu.com or https://launchpad.net and look in the error console.
You will see this message:

site : potentially vulnerable to cve-2009-3555

Cause
=====

We have disabled part of the TLS in order to prevent being affected by the mentioned CVE - launchpad is not vulnerable, and the browser warning is spurious : https://bugzilla.mozilla.org/show_bug.cgi?id=554594 documents this.

We will in due course have a newer libopenssl deployed onto our servers, but as this is, at most, cosmetic we're not planning on a special deployment for the moment - we will run with the version that is in Ubuntu's current LTS release. As of August 2010 Launchpad is about to upgrade to Lucid, which may give us the newer libopenssl.

Workaround
==========

Ignore the warning in your browser.

CVE References

Revision history for this message
Rickard Närström (riccetn) wrote :

This is if I understand it correctly problem at those sites and not Ubuntu itself. I have assigned launchpad to this how to deal with wiki.ubuntu.com?

Changed in ubuntu:
status: New → Invalid
security vulnerability: no → yes
Curtis Hovey (sinzui)
affects: launchpad → launchpad-foundations
Revision history for this message
Matthew Nuzum (newz) wrote :

Hi, I can confirm that the error console does indeed say this, however it's not clear to me what the impact of this is on our systems. This issue was addressed in USN 860-1 http://www.ubuntu.com/usn/USN-860-1. Herb has stated that our systems are up to date but if the sysadmins can confirm this and close this bug it would be great.

Changed in ubuntu-website:
assignee: nobody → The Canonical Sysadmins (canonical-sysadmins)
Revision history for this message
Matthew Nuzum (newz) wrote :

Hi, pasting from IRC:

(11:52:57 AM) jdstrand: herb, newz2000: I did that apache update, and it is not vulnerable to client initiated TLS renegotiation
(11:53:18 AM) jdstrand: herb, newz2000: however, it is still vulnerable to server initiated renegotiation
(11:53:40 AM) jdstrand: herb, newz2000: and there are mitigations in the USN
(11:54:11 AM) jdstrand: herb, newz2000: you can see http://people.canonical.com/~ubuntu-security/cve/2009/CVE-2009-3555.html for a lot of details
(11:54:31 AM) jdstrand: herb, newz2000: mdeslaur from our team is the most up to date on the issue however
(11:55:41 AM) jdstrand: CVE-2009-3555 requires a protocol change to fully address the issue. however, for apache, you can configure apache to not be vulnerable
(11:56:01 AM) jdstrand: (with the patch from the usn)

Revision history for this message
Gary Poster (gary) wrote :

LOSAs verify that LP has the patch installed.

They will track further Apache updates, once the protocol change has been agreed upon and implemented.

Changed in launchpad-foundations:
status: New → Fix Released
Revision history for this message
Gary Poster (gary) wrote :

I didn't think there was a way around this yet, but https://bugzilla.mozilla.org/show_bug.cgi?id=554594#c8 seems to suggest that an update to a newer openssl will make our users no longer worried about the problem.

I'm reopening the bug for Foundations and will make an RT.

Changed in launchpad-foundations:
status: Fix Released → Triaged
importance: Undecided → High
Revision history for this message
Gary Poster (gary) wrote :

To be clear, the problem is not the potential vulnerability--IS has assured that we are not vulnerable. The concern is that more than half of Launchpad's users are Firefox users, and we want to keep them from being concerned about Launchpad, and keep us from having to reply to security questions about this issue.

Revision history for this message
Gary Poster (gary) wrote :

RT #40432

Gary Poster (gary)
Changed in launchpad-foundations:
assignee: nobody → Robert Collins (lifeless)
Revision history for this message
Alex Mayorga (alex-mayorga) wrote :

I'm here from the duplicate.
FWIW these are also flagged by Firefox trunk as of today:
launchpad.net : server does not support RFC 5746, see CVE-2009-3555
edge.launchpad.net : server does not support RFC 5746, see CVE-2009-3555
launchpadlibrarian.net : server does not support RFC 5746, see CVE-2009-3555

Revision history for this message
Robert Collins (lifeless) wrote : Re: [Bug 566467] Re: potentially vulnerable to cve-2009-3555

In what way is it flagged? In the error log? In the main UI? Somewhere else?

Revision history for this message
Stuart Bishop (stub) wrote :

On Mon, Jul 19, 2010 at 10:33 PM, Robert Collins
<email address hidden> wrote:
> In what way is it flagged? In the error log? In the main UI? Somewhere
> else?

The Firefox error console (Tools -> Error Console)

--
Stuart Bishop <email address hidden>
http://www.stuartbishop.net/

Revision history for this message
Sam_ (and-sam) wrote :

$ LANGUAGE=C apt-cache policy firefox
firefox:
  Installed: 3.6.8+build1+nobinonly-0ubuntu0.10.04.1
  Candidate: 3.6.8+build1+nobinonly-0ubuntu0.10.04.1
  Version table:
 *** 3.6.8+build1+nobinonly-0ubuntu0.10.04.1 0
        500 http://archive.ubuntu.com/ubuntu/ lucid-updates/main Packages
        500 http://archive.ubuntu.com/ubuntu/ lucid-security/main Packages
        100 /var/lib/dpkg/status
     3.6.3+nobinonly-0ubuntu4 0
        500 http://archive.ubuntu.com/ubuntu/ lucid/main Packages

Changed in launchpad-foundations:
status: Triaged → Won't Fix
description: updated
Revision history for this message
Amahdy (amahdy) wrote :

Any progress for this?
I heard that this bug resolution needs couple of upgrades for:
Apache, mod_ssl, and openssl
All the latest available versions on Ubuntu repository does not contain the resolution, this bug affects launchpad as well as everybody who uses an Ubuntu server like me...

I know that redhat and fedora just released fix for this by upgrading Apache to version 2.2.15 (currently on Ubuntu it's 2.2.14)

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

@Amahdy:

It is currently fixed in Maverick.

Updated openssl and apache2 packages will appear in -proposed for earlier releases probably next week.

See bug #616759 for tracking.

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Updated packages have been released for stable releases

http://www.ubuntu.com/usn/usn-990-1
http://www.ubuntu.com/usn/usn-990-2

Matthew Nuzum (newz)
Changed in ubuntu-website:
status: New → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Duplicates of this bug

Other bug subscribers

Related questions

Remote bug watches

Bug watches keep track of this bug in other bug trackers.