A flaw was found where authconfig could configure sssd in a way that treats existing and non-existing logins differently, leaking information on existence of a user. An attacker with physical or network access to the machine could enumerate users via a timing attack. (CVE-2017-7488) SL7 x86_64 authconfig-6.2.8-30.el7.x86_64.rpm authconfig-debuginfo-6.2.8-30.el7.x86_64.rpm authco [More...]. Synopsis: Moderate: authconfig security, bug fix, and Advisory ID: SLSA-2017:2285-1 Issue Date: 2017-08-01 CVE Numbers: CVE-2017-7488 -- Security Fix(es): * A flaw was found where authconfig could configure sssd in a way that treats existing and non-existing logins differently, leaking information on existence of a user. An attacker with physical or network access to the machine could enumerate users via a timing attack. (CVE-2017-7488) -- SL7 x86_64 authconfig-6.2.8-30.el7.x86_64.rpm authconfig-debuginfo-6.2.8-30.el7.x86_64.rpm authconfig-gtk-6.2.8-30.el7.x86_64.rpm - Scientific Linux Development Team . Examination of authconfig's vulnerability uncovers a crucial security update aimed at mitigating risks associated with user enumeration vulnerabilities in SL7.. authconfig fix, timing attack mitigation, SL7 security update, user enumeration risk, moderate issue resolution. . LinuxSecurity.com Team
New release fixing moderate (information leak) issue with PAM configuration when authentication to remote services via SSSD is enabled. To fix the incorrect configuration run: authconfig --updateall. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-1fe6f25af9 2017-06-09 18:48:36.533330 --------------------------------------------------------------------------------Name : authconfig Product : Fedora 26 Version : 7.0.1 Release : 1.fc26 URL : https://pagure.io/authconfig Summary : Command line tool for setting up authentication from network services Description : Authconfig is a command line utility which can configure a workstation to use shadow (more secure) passwords. Authconfig can also configure a system to be a client for certain networked user information and authentication schemes. --------------------------------------------------------------------------------Update Information: New release fixing moderate (information leak) issue with PAM configuration when authentication to remote services via SSSD is enabled. To fix the incorrect configuration run: authconfig --updateall --------------------------------------------------------------------------------References: [ 1 ] Bug #1441604 - CVE-2017-7488 authconfig: Information leak when SSSD is used for authentication against remote server https://bugzilla.redhat.com/show_bug.cgi?id=1441604 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade authconfig' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.