Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Fedora 21: FEDORA-2015-6392 Moderate Cherokee Authentication Bypass

fedora
Calendar Grey April 27, 2015
Dist Fedora Esm H88
Cherokee web server patch addresses critical security loophole associated with LDAP authentication. It is advised to enhance security on Fedora 21 setups.
Resolves bz 1114461 - CVE-2014-4668 cherokee: authentication bypass when LDAP server allows unauthenticated binds

Summary

Cherokee is a very fast, flexible and easy to configure Web Server. It supports

the widespread technologies nowadays: FastCGI, SCGI, PHP, CGI, TLS and SSL

encrypted connections, Virtual hosts, Authentication, on the fly encoding,

Apache compatible log files, and much more.

Update Information:

Resolves bz 1114461 - CVE-2014-4668 cherokee: authentication bypass when LDAP server allows unauthenticated binds

Change Log

* Wed Apr 15 2015 Pavel Lisý - 1.2.103-6 - Resolves bz 1114461 - CVE-2014-4668 cherokee: authentication bypass when LDAP server allows unauthenticated binds - Resolves bz 1094901 - cherokee: script and/or trigger should not directly enable systemd units - Resolves bz 959170 - cherokee-worker and cherokee-admin want to use execstack (EL5)

References


[ 1 ] Bug #1114461 - CVE-2014-4668 cherokee: authentication bypass when LDAP server allows unauthenticated binds [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1114461 [ 2 ] Bug #1094901 - cherokee: script and/or trigger should not directly enable systemd units https://bugzilla.redhat.com/show_bug.cgi?id=1094901

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update cherokee' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
important
Lowest
Low
Medium
High
Critical

Name: cherokee
Product: Fedora 21
Version: 1.2.103
Release: 6.fc21
Summary: Flexible and Fast Webserver

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here