CVE-2014-3504
published 2014-08-19CVE-2014-3504: The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly…
PriorityP424medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
3.15%
86.6th percentile
The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
Affected
99 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
serf vulnerability
vendor_ubuntu·2014-08-14
CVE-2014-3504 serf vulnerability
Title: serf vulnerability
Summary: Fraudulent security certificates could allow sensitive information to
be exposed when accessing the Internet.
Ben Reser discovered that serf did not correctly handle SSL certificates
with NUL bytes in the CommonName or SubjectAltNames fields. A remote
attacker could exploit this to perform a machine-in-the-middle attack to view
sensitive information or alter encrypted communications.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2014-3504: serf - The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_c...
vendor_debian·2014·CVSS 4.0
CVE-2014-3504 [MEDIUM] CVE-2014-3504: serf - The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_c...
The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
Scope: local
bookworm: resolved (fixed in 1.3.7-1)
bullseye: resolved (fixed in 1.3.7-1)
forky: resolved (fixed in 1.3.7-1)
sid: resolved (fixed in 1.3.7-1)
trixie: resolved (fixed in 1.3.7-1)
GHSA
GHSA-4425-mwr9-99xc: The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0
ghsa_unreviewed·2022-05-14
CVE-2014-3504 [MEDIUM] GHSA-4425-mwr9-99xc: The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0
The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
OSV
CVE-2014-3504: The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0
osv·2014-08-19·CVSS 4.0
CVE-2014-3504 [MEDIUM] CVE-2014-3504: The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0
The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3504 libserf: failure to properly handle a NUL character in the CommonName or SubjectAltNames fields
bugzilla·2014-08-12·CVSS 4.0
CVE-2014-3504 [MEDIUM] CVE-2014-3504 libserf: failure to properly handle a NUL character in the CommonName or SubjectAltNames fields
CVE-2014-3504 libserf: failure to properly handle a NUL character in the CommonName or SubjectAltNames fields
A flaw was found in the way Serf handled NUL characters in the CommonName and SubjectAltNames fields of X.509 certificates. An attacker able to get a carefully-crafted certificate signed by a trusted Certificate Authority could trick applications using Serf (such as Subversion on Fedora 20 and later, refer also to bug 1127063) into accepting it by mistake, allowing the attacker to perform a man-in-the-middle attack.
Serf versions 0.2.0 through 1.3.6 are vulnerable. It has been fixed in upstream version 1.3.7.
Upstream fix:
https://code.google.com/p/serf/source/detail?r=2392
Upstream advisory:
https://groups.google.com/forum/#!topic/serf-dev/NvgPoK6sFsc
Acknowledgements:
Red
Bugzilla
CVE-2014-3504 libserf: failure to properly handle a NUL character in the CommonName or SubjectAltNames fields [epel-7]
bugzilla·2014-08-12·CVSS 4.0
CVE-2014-3504 [MEDIUM] CVE-2014-3504 libserf: failure to properly handle a NUL character in the CommonName or SubjectAltNames fields [epel-7]
CVE-2014-3504 libserf: failure to properly handle a NUL character in the CommonName or SubjectAltNames fields [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tra
Bugzilla
CVE-2014-3504 libserf: failure to properly handle a NUL character in the CommonName or SubjectAltNames fields [fedora-all]
bugzilla·2014-08-12·CVSS 4.0
CVE-2014-3504 [MEDIUM] CVE-2014-3504 libserf: failure to properly handle a NUL character in the CommonName or SubjectAltNames fields [fedora-all]
CVE-2014-3504 libserf: failure to properly handle a NUL character in the CommonName or SubjectAltNames fields [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2014-3504 libserf: failure to properly handle a NUL character in the CommonName or SubjectAltNames fields [epel-6]
bugzilla·2014-08-12·CVSS 4.0
CVE-2014-3504 [MEDIUM] CVE-2014-3504 libserf: failure to properly handle a NUL character in the CommonName or SubjectAltNames fields [epel-6]
CVE-2014-3504 libserf: failure to properly handle a NUL character in the CommonName or SubjectAltNames fields [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-6 tra
http://lists.opensuse.org/opensuse-updates/2014-08/msg00038.htmlhttp://secunia.com/advisories/59584http://secunia.com/advisories/60721http://ubuntu.com/usn/usn-2315-1http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.securityfocus.com/bid/69238https://groups.google.com/forum/#%21topic/serf-dev/NvgPoK6sFschttps://security.gentoo.org/glsa/201610-05https://subversion.apache.org/security/CVE-2014-3522-advisory.txthttp://lists.opensuse.org/opensuse-updates/2014-08/msg00038.htmlhttp://secunia.com/advisories/59584http://secunia.com/advisories/60721http://ubuntu.com/usn/usn-2315-1http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.securityfocus.com/bid/69238https://groups.google.com/forum/#%21topic/serf-dev/NvgPoK6sFschttps://security.gentoo.org/glsa/201610-05https://subversion.apache.org/security/CVE-2014-3522-advisory.txt
2014-08-19
Published