Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Mageia: 2020-0295 Moderate: Cloud-Init Password Prediction Problems

mageia
Calendar Grey July 31, 2020
Dist Mageia Esm H88
Revised Docker compositional files address vulnerabilities related to exposure of sensitive data. Made available on August 15, 2021.
In cloud-init, relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.ch...

Summary

In cloud-init, relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function (CVE-2020-8631).
In cloud-init, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords (CVE-2020-8632).

References

- https://bugs.mageia.org/show_bug.cgi?id=26236

- https://lists.debian.org/debian-lts-announce/2020/02/msg00021.html

- https://www.cve.org/CVERecord?id=CVE-2020-8631

- https://www.cve.org/CVERecord?id=CVE-2020-8632

Resolution

SRPMS

- 7/core/cloud-init-0.7.5-7.1.mga7

Publication date: 31 Jul 2020
URL: https://advisories.mageia.org/MGASA-2020-0295.html
Type: security
CVE: CVE-2020-8631, CVE-2020-8632

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here