phpCAS before 1.3.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
- Signature Spoofing by Key Recreation An attacker obtains an authoritative or reputable signer's private signature key by exploiting a cryptographic weakness in the signature algorithm or pseudorandom number generation and then uses this key to forge signatures from the original signer to mislead a victim into performing actions that benefit the attacker.
NASL family Fedora Local Security Checks NASL id FEDORA_2012-21106.NASL description Changes in version 1.3.2 Security Fixes : - CVE-2012-5583 Missing CN validation of CAS server certificate [#58] (Joachim Fritschi) Bug Fixes : - Fix broken character encoding in Greek and French [#40] (Joachim Fritschi) - Minor error corrections in a few example files [] (Joachim Fritschi) - Remove erroneous break statement [#44] (jbittel) - Use X-Forwarded-Port [#45] (Andrew Kirkpatrick) - Stop autoloader using set_include_path [#51/#52] (drysdaleb) - Fix undefined property in the rebroadcast code [#47] (Joachim Fritschi) Improvement : - Enable getCookies on a proxied sevices [#56] (Adam Franco) Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues." ); # script_set_attribute( attribute:"see_also", value:"" ); script_set_attribute( attribute:"solution", value:"Update the affected php-pear-CAS package." );
