A GnuTLS bug skips certificate checks
Summary
Dan Goodin describes a control flow bug in GnuTLS that caused invalid certificates to be wrongly accepted as valid. Several Linux applications used the library. Distributions released security updates at short notice.
Ideas
- A wrong return value skipped parts of the certificate validation.
- Certain error paths accidentally reported success.
- Applications trusted the library's decision without checking for themselves.
- A small control flow problem broke the entire authentication.
Insights
- Cryptography fails more often because of integration than because of mathematics.
- Error paths deserve the same depth of testing as successful flows.
- Shared libraries multiply the reach of individual bugs.
Facts
- The hole affected GnuTLS.
Recommendations
- Update GnuTLS packages on supported systems.
- Test certificate errors with deliberately invalid chains.
References
Links to the original source and the Web Archive open in a new tab.