Re: Question regarding Saxon-C 1.2.1 glibc vulnerability report
Michael Kay <mike-JkSD5nQpfvpWk0Htik3J/[email protected]> Fri, 16 Jul 2021 10:17:57 +0100
| Newsgroups | gmane.text.xml.saxon.help |
|---|---|
| Message-ID | <[email protected]> |
--===============9195140799596087739== Content-Type: multipart/alternative; boundary="Apple-Mail=_EB44A451-0324-4F89-A49F-52B18ADD9B09" --Apple-Mail=_EB44A451-0324-4F89-A49F-52B18ADD9B09 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=us-ascii There are 108 vulnerabilities in glibc listed at [1] and this is number = 40; its severity rating is well down the list, so it's not at all clear = why they've singled out this particular one. It only happens under very = specific circumstances and I guess we could check the Saxon source code = to provide an assurance that we aren't invoking the relevant interface. = But doing that for all 108 vulnerabilities iin glibc certainly isn't = something we can undertake. The problem with these automated scans is that they generate a vast = number of false alarms. Frankly, I'm bemused by the whole thing. Someone who has access to glibc = and iconv can surely trigger an infinite loop without any difficulty = whatsoever. Indeed, anyone with access to an XSLT processor can do so = easily enough. There's no way you should be allowing untrusted users = access to such interfaces. Unfortunately this kind of reasoning doesn't appeal to the people for = whom security assessment means "run the checking tool and tick the = boxes". Michael Kay Saxonica [1] = https://www.cvedetails.com/vulnerability-list.php?vendor_id=3D72&product_i= d=3D767&version_id=3D0&page=3D1&hasexp=3D0&opdos=3D0&opec=3D0&opov=3D0&opc= srf=3D0&opgpriv=3D0&opsqli=3D0&opxss=3D0&opdirt=3D0&opmemc=3D0&ophttprs=3D= 0&opbyp=3D0&opfileinc=3D0&opginf=3D0&cvssscoremin=3D0&cvssscoremax=3D0&yea= r=3D0&cweid=3D0&order=3D1&trc=3D108&sha=3D5e0c40399ffafd65f77e6b537bcc0f50= 474eeed3 > On 15 Jul 2021, at 21:37, Craeg Strong <cstrong-6O6vo0wUA9s4yJ9dIELTZQC/[email protected]> = wrote: >=20 > Greetings! > We are using Saxon-C v1.2.1 to provide XSLT 3.0 processing support for = a US Govt agency (Python flavor). > We provided a release to the agency with all our XML/XSLT/XSD sources, = tests, scripts, etc. The solution works well and all looked good. > The agency recently did a Black Duck cyber security scan on the = software we provided and sent us the report. > The report indicates a number of high-priority vulnerabilities in GNU = glibc 2.31 and gconv > I noticed that the latest version of glibc is 2.33 > I have no idea if the latest version would actually resolve these = issues or not: > The GNU C Library (glibc) is vulnerable to a denial-of-service (DoS) = issue due to the presence of an infinite loop flaw in the iconv program. >=20 > An attacker could invoke the iconv program with the -c option and = supply a crafted input in order to trigger the infinite loop and cause a = iconv to hang. This problem is caused by how the front-end mishandles = multiple suffixes. In this case, the first suffix is the only one that = is taken into account such that errors were not ignored correctly. >=20 > I apologize for my ignorance regarding this; it has been 20 years = since I have coded in C/C++.=20 > I just wanted to run it by this list to see if anyone has insight. I = can imagine several possibilities: > =20 > This is a known issue, fixed in the latest glibc, and therefore the = fix will be automatically inherited by the next release of Saxon-C, = whenever that happens > This is a spurious or irrelevant report and indicates that the Black = Duck cyber tool has not been calibrated correctly > This is a known vulnerability with gconv/iconv and is not something = fixable. We live with it and mitigate the risk in other ways (like = firewalls) > =20 > Appreciate any advice, breadcrumbs, URLs anyone can provide. > Thanks, > --Craeg > =20 > Craeg Strong | CTO > | Savant Financial Technologies, Inc. d/b/a Ariel Partners | = cstrong-6O6vo0wUA9s4yJ9dIELTZQC/[email protected] <mailto:cstrong-6O6vo0wUA9s4yJ9dIELTZQC/[email protected]> | = 917-992-0259 > =20 > =20 > =20 > _______________________________________________ > saxon-help mailing list archived at http://saxon.markmail.org/ = <http://saxon.markmail.org/> > [email protected] = <mailto:[email protected]> > https://lists.sourceforge.net/lists/listinfo/saxon-help = <https://lists.sourceforge.net/lists/listinfo/saxon-help> --Apple-Mail=_EB44A451-0324-4F89-A49F-52B18ADD9B09 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=us-ascii <html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; = charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; = -webkit-nbsp-mode: space; line-break: after-white-space;" class=3D"">There= are 108 vulnerabilities in glibc listed at [1] and this is number 40; = its severity rating is well down the list, so it's not at all clear why = they've singled out this particular one. It only happens under very = specific circumstances and I guess we could check the Saxon source code = to provide an assurance that we aren't invoking the relevant interface. = But doing that for all 108 vulnerabilities iin glibc certainly isn't = something we can undertake.<div class=3D""><br class=3D""></div><div = class=3D"">The problem with these automated scans is that they generate = a vast number of false alarms.</div><div class=3D""><br = class=3D""></div><div class=3D"">Frankly, I'm bemused by the whole = thing. Someone who has access to glibc and iconv can surely trigger an = infinite loop without any difficulty whatsoever. Indeed, anyone with = access to an XSLT processor can do so easily enough. There's no way you = should be allowing untrusted users access to such interfaces.</div><div = class=3D""><br class=3D""></div><div class=3D"">Unfortunately this kind = of reasoning doesn't appeal to the people for whom security assessment = means "run the checking tool and tick the boxes".</div><div class=3D""><br= class=3D""></div><div class=3D"">Michael Kay</div><div = class=3D"">Saxonica<br class=3D""><div class=3D""><br = class=3D""></div><div class=3D""><br class=3D""></div><div class=3D""><br = class=3D""></div><div class=3D""><br class=3D""></div><div class=3D""><br = class=3D""></div><div class=3D"">[1] <a = href=3D"https://www.cvedetails.com/vulnerability-list.php?vendor_id=3D72&a= mp;product_id=3D767&version_id=3D0&page=3D1&hasexp=3D0&opd= os=3D0&opec=3D0&opov=3D0&opcsrf=3D0&opgpriv=3D0&opsqli= =3D0&opxss=3D0&opdirt=3D0&opmemc=3D0&ophttprs=3D0&opby= p=3D0&opfileinc=3D0&opginf=3D0&cvssscoremin=3D0&cvssscorem= ax=3D0&year=3D0&cweid=3D0&order=3D1&trc=3D108&sha=3D5e= 0c40399ffafd65f77e6b537bcc0f50474eeed3" = class=3D"">https://www.cvedetails.com/vulnerability-list.php?vendor_id=3D7= 2&product_id=3D767&version_id=3D0&page=3D1&hasexp=3D0&= opdos=3D0&opec=3D0&opov=3D0&opcsrf=3D0&opgpriv=3D0&ops= qli=3D0&opxss=3D0&opdirt=3D0&opmemc=3D0&ophttprs=3D0&o= pbyp=3D0&opfileinc=3D0&opginf=3D0&cvssscoremin=3D0&cvsssco= remax=3D0&year=3D0&cweid=3D0&order=3D1&trc=3D108&sha=3D= 5e0c40399ffafd65f77e6b537bcc0f50474eeed3</a><br class=3D""><div><br = class=3D""><blockquote type=3D"cite" class=3D""><div class=3D"">On 15 = Jul 2021, at 21:37, Craeg Strong <<a = href=3D"mailto:cstrong-6O6vo0wUA9s4yJ9dIELTZQC/[email protected]" = class=3D"">cstrong-6O6vo0wUA9s4yJ9dIELTZQC/[email protected]</a>> wrote:</div><br = class=3D"Apple-interchange-newline"><div class=3D""><meta = charset=3D"UTF-8" class=3D""><div class=3D"WordSection1" style=3D"page: = WordSection1; caret-color: rgb(0, 0, 0); font-family: Helvetica; = font-size: 13px; font-style: normal; font-variant-caps: normal; = font-weight: normal; letter-spacing: normal; text-align: start; = text-indent: 0px; text-transform: none; white-space: normal; = word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: = none;"><div style=3D"margin: 0in; font-size: 11pt; font-family: Calibri, = sans-serif;" class=3D"">Greetings!<o:p class=3D""></o:p></div><div = style=3D"margin: 0in; font-size: 11pt; font-family: Calibri, = sans-serif;" class=3D"">We are using Saxon-C v1.2.1 to provide XSLT 3.0 = processing support for a US Govt agency (Python flavor).<o:p = class=3D""></o:p></div><div style=3D"margin: 0in; font-size: 11pt; = font-family: Calibri, sans-serif;" class=3D"">We provided a release to = the agency with all our XML/XSLT/XSD sources, tests, scripts, = etc. The solution works well and all looked good.<o:p = class=3D""></o:p></div><div style=3D"margin: 0in; font-size: 11pt; = font-family: Calibri, sans-serif;" class=3D"">The agency recently did a = Black Duck cyber security scan on the software we provided and sent us = the report.<o:p class=3D""></o:p></div><div style=3D"margin: 0in; = font-size: 11pt; font-family: Calibri, sans-serif;" class=3D"">The = report indicates a number of high-priority vulnerabilities in GNU glibc = 2.31 and gconv<o:p class=3D""></o:p></div><div style=3D"margin: 0in; = font-size: 11pt; font-family: Calibri, sans-serif;" class=3D"">I noticed = that the latest version of glibc is 2.33<o:p class=3D""></o:p></div><div = style=3D"margin: 0in; font-size: 11pt; font-family: Calibri, = sans-serif;" class=3D"">I have no idea if the latest version would = actually resolve these issues or not:<o:p class=3D""></o:p></div><p = style=3D"background-color: rgb(242, 242, 242); background-position: = initial initial; background-repeat: initial initial;" class=3D""><span = style=3D"font-size: 10pt; font-family: NotoSans, serif;" class=3D"">The = GNU C Library (glibc) is vulnerable to a denial-of-service (DoS) issue = due to the presence of an infinite loop flaw in the iconv = program.</span><o:p class=3D""></o:p></p><p style=3D"background-color: = rgb(242, 242, 242); background-position: initial initial; = background-repeat: initial initial;" class=3D""><span style=3D"font-size: = 10pt; font-family: NotoSans, serif;" class=3D"">An attacker could invoke = the iconv program with the -c option and supply a crafted input in order = to trigger the infinite loop and cause a iconv to hang. This problem is = caused by how the front-end mishandles multiple suffixes. In this case, = the first suffix is the only one that is taken into account such that = errors were not ignored correctly.</span><o:p class=3D""></o:p></p><div = style=3D"margin: 0in; font-size: 11pt; font-family: Calibri, = sans-serif;" class=3D"">I apologize for my ignorance regarding this; it = has been 20 years since I have coded in C/C++. <o:p = class=3D""></o:p></div><div style=3D"margin: 0in; font-size: 11pt; = font-family: Calibri, sans-serif;" class=3D"">I just wanted to run it by = this list to see if anyone has insight. I can imagine several = possibilities:<o:p class=3D""></o:p></div><div style=3D"margin: 0in; = font-size: 11pt; font-family: Calibri, sans-serif;" class=3D""><o:p = class=3D""> </o:p></div><ol start=3D"1" type=3D"1" = style=3D"margin-bottom: 0in; margin-top: 0in;" class=3D""><li = class=3D"MsoListParagraph" style=3D"margin: 0in; font-size: 11pt; = font-family: Calibri, sans-serif;">This is a known issue, fixed in the = latest glibc, and therefore the fix will be automatically inherited by = the next release of Saxon-C, whenever that happens<o:p = class=3D""></o:p></li><li class=3D"MsoListParagraph" style=3D"margin: = 0in; font-size: 11pt; font-family: Calibri, sans-serif;">This is a = spurious or irrelevant report and indicates that the Black Duck cyber = tool has not been calibrated correctly<o:p class=3D""></o:p></li><li = class=3D"MsoListParagraph" style=3D"margin: 0in; font-size: 11pt; = font-family: Calibri, sans-serif;">This is a known vulnerability with = gconv/iconv and is not something fixable. We live with it and = mitigate the risk in other ways (like firewalls)<o:p = class=3D""></o:p></li></ol><div style=3D"margin: 0in; font-size: 11pt; = font-family: Calibri, sans-serif;" class=3D""><o:p = class=3D""> </o:p></div><div style=3D"margin: 0in; font-size: 11pt; = font-family: Calibri, sans-serif;" class=3D"">Appreciate any advice, = breadcrumbs, URLs anyone can provide.<o:p class=3D""></o:p></div><div = style=3D"margin: 0in; font-size: 11pt; font-family: Calibri, = sans-serif;" class=3D"">Thanks,<o:p class=3D""></o:p></div><div = style=3D"margin: 0in; font-size: 11pt; font-family: Calibri, = sans-serif;" class=3D"">--Craeg<o:p class=3D""></o:p></div><div = style=3D"margin: 0in; font-size: 11pt; font-family: Calibri, = sans-serif;" class=3D""><o:p class=3D""> </o:p></div><div = class=3D""><div style=3D"margin: 0in; font-size: 11pt; font-family: = Calibri, sans-serif;" class=3D""><b class=3D""><span style=3D"font-family:= "Times New Roman", serif; color: rgb(31, 73, 125);" = class=3D"">Craeg Strong | CTO</span></b><span style=3D"font-size: 12pt;" = class=3D""><o:p class=3D""></o:p></span></div><div style=3D"margin: 0in; = font-size: 11pt; font-family: Calibri, sans-serif;" class=3D""><span = style=3D"font-family: "Times New Roman", serif; color: rgb(31, = 73, 125);" class=3D""> | Savant Financial Technologies, Inc. d/b/a = Ariel Partners | <a href=3D"mailto:cstrong-6O6vo0wUA9s4yJ9dIELTZQC/[email protected]" = class=3D""><span style=3D"color: purple;" = class=3D"">cstrong-6O6vo0wUA9s4yJ9dIELTZQC/[email protected]</span></a> </span><span = style=3D"font-size: 11.5pt; font-family: "Times New Roman", = serif; color: rgb(31, 73, 125);" class=3D"">| 917-992-0259</span><span = style=3D"font-size: 12pt;" class=3D""><o:p = class=3D""></o:p></span></div></div><div style=3D"margin: 0in; = font-size: 11pt; font-family: Calibri, sans-serif;" class=3D""><o:p = class=3D""> </o:p></div><div style=3D"margin: 0in; font-size: 11pt; = font-family: Calibri, sans-serif;" class=3D""><o:p = class=3D""> </o:p></div><div style=3D"margin: 0in; font-size: 11pt; = font-family: Calibri, sans-serif;" class=3D""><o:p = class=3D""> </o:p></div></div><span style=3D"caret-color: rgb(0, 0, = 0); font-family: Helvetica; font-size: 13px; font-style: normal; = font-variant-caps: normal; font-weight: normal; letter-spacing: normal; = text-align: start; text-indent: 0px; text-transform: none; white-space: = normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; = text-decoration: none; float: none; display: inline !important;" = class=3D"">_______________________________________________</span><br = style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: = 13px; font-style: normal; font-variant-caps: normal; font-weight: = normal; letter-spacing: normal; text-align: start; text-indent: 0px; = text-transform: none; white-space: normal; word-spacing: 0px; = -webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span = style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: = 13px; font-style: normal; font-variant-caps: normal; font-weight: = normal; letter-spacing: normal; text-align: start; text-indent: 0px; = text-transform: none; white-space: normal; word-spacing: 0px; = -webkit-text-stroke-width: 0px; text-decoration: none; float: none; = display: inline !important;" class=3D"">saxon-help mailing list archived = at<span class=3D"Apple-converted-space"> </span></span><a = href=3D"http://saxon.markmail.org/" style=3D"font-family: Helvetica; = font-size: 13px; font-style: normal; font-variant-caps: normal; = font-weight: normal; letter-spacing: normal; orphans: auto; text-align: = start; text-indent: 0px; text-transform: none; white-space: normal; = widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; = -webkit-text-stroke-width: 0px;" = class=3D"">http://saxon.markmail.org/</a><br style=3D"caret-color: = rgb(0, 0, 0); font-family: Helvetica; font-size: 13px; font-style: = normal; font-variant-caps: normal; font-weight: normal; letter-spacing: = normal; text-align: start; text-indent: 0px; text-transform: none; = white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; = text-decoration: none;" class=3D""><a = href=3D"mailto:[email protected]" style=3D"font-family: = Helvetica; font-size: 13px; font-style: normal; font-variant-caps: = normal; font-weight: normal; letter-spacing: normal; orphans: auto; = text-align: start; text-indent: 0px; text-transform: none; white-space: = normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; = -webkit-text-stroke-width: 0px;" = class=3D"">[email protected]</a><br style=3D"caret-color: = rgb(0, 0, 0); font-family: Helvetica; font-size: 13px; font-style: = normal; font-variant-caps: normal; font-weight: normal; letter-spacing: = normal; text-align: start; text-indent: 0px; text-transform: none; = white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; = text-decoration: none;" class=3D""><a = href=3D"https://lists.sourceforge.net/lists/listinfo/saxon-help" = style=3D"font-family: Helvetica; font-size: 13px; font-style: normal; = font-variant-caps: normal; font-weight: normal; letter-spacing: normal; = orphans: auto; text-align: start; text-indent: 0px; text-transform: = none; white-space: normal; widows: auto; word-spacing: 0px; = -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;" = class=3D"">https://lists.sourceforge.net/lists/listinfo/saxon-help</a><spa= n style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: = 13px; font-style: normal; font-variant-caps: normal; font-weight: = normal; letter-spacing: normal; text-align: start; text-indent: 0px; = text-transform: none; white-space: normal; word-spacing: 0px; = -webkit-text-stroke-width: 0px; text-decoration: none; float: none; = display: inline !important;" = class=3D""></span></div></blockquote></div><br = class=3D""></div></div></body></html>= --Apple-Mail=_EB44A451-0324-4F89-A49F-52B18ADD9B09-- --===============9195140799596087739== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============9195140799596087739== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ saxon-help mailing list archived at http://saxon.markmail.org/ [email protected] https://lists.sourceforge.net/lists/listinfo/saxon-help --===============9195140799596087739==--