Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Wed, 05 Nov 2014 13:51:25 -0700
From: "Vincent Danen" <vdanen@...hat.com>
To: "OSS Security List" <oss-security@...ts.openwall.com>
Subject: CVE-2014-7828 FreeIPA 4.0/4.1 does not require password when OTP used

Just a heads-up that FreeIPA 4.0 and 4.1 (_not_ earlier versions), when 
OTP is used, did not requite the password (or second factor of 2FA) to 
login.

https://fedorahosted.org/freeipa/ticket/4690
https://bugzilla.redhat.com/show_bug.cgi?id=1160871
This was assigned CVE-2014-7828.  A patch to fix it is available:

https://www.redhat.com/archives/freeipa-devel/2014-November/msg00068.html

Upstream is recommending users disable 2FA until they can get a fix out 
tomorrow:

https://www.redhat.com/archives/freeipa-users/2014-November/msg00077.html

-- 
Vincent Danen / Red Hat Product Security

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.