ZNC SSL listeners are vulnerable to POODLE.
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
znc (Ubuntu) |
Fix Released
|
Medium
|
Unassigned | ||
Precise |
Won't Fix
|
Medium
|
Unassigned | ||
Trusty |
Confirmed
|
Medium
|
Unassigned | ||
Utopic |
Won't Fix
|
Medium
|
Unassigned | ||
Vivid |
Fix Released
|
Medium
|
Unassigned |
Bug Description
This is a report on the state of the ZNC package in Ubuntu.
Currently, the ZNC package is vulnerable to CVE-2014-3566 and the POODLE vulnerability. It does not disable SSLv3 and does not permit an individual to change what is or is not enabled in SSL protocols.
An upstream ZNC issue was opened on this issue, requesting that the insecure SSLv2 and SSLv3 are disabled, as well as a request to be able to specify the SSL Ciphers to be used. That issue is at https:/
https:/
The related CVE is the OpenSSL POODLE vulnerability - CVE-2014-3566.
All versions of the ZNC software are affected at this time.
CVE References
tags: | added: poodle |
Changed in znc (Ubuntu Utopic): | |
status: | New → Confirmed |
Changed in znc (Ubuntu Trusty): | |
status: | New → Confirmed |
Changed in znc (Ubuntu Precise): | |
status: | New → Confirmed |
Changed in znc (Ubuntu Utopic): | |
status: | Confirmed → Won't Fix |
Changed in znc (Ubuntu): | |
importance: | Undecided → Medium |
Changed in znc (Ubuntu Precise): | |
importance: | Undecided → Medium |
Changed in znc (Ubuntu Trusty): | |
importance: | Undecided → Medium |
Changed in znc (Ubuntu Utopic): | |
importance: | Undecided → Medium |
Changed in znc (Ubuntu Vivid): | |
importance: | Undecided → Medium |
Discussion in #ubuntu-hardened with mdeslaur has made a point: We don't wish to disable SSLv3 in the stable versions currently in the packages.
There are upstream code reviews in progress for an option to disable SSL protocols in the configuration file, and that may be an acceptable alternative change.