Bug 21112 - perl-rt-authen-externalauth security vulnerability CVE-2017-5361
Summary: perl-rt-authen-externalauth security vulnerability CVE-2017-5361
Status: RESOLVED INVALID
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Mageia Bug Squad
QA Contact: Sec team
URL: https://www.debian.org/security/2017/...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-06-19 10:47 CEST by Zombie Ryushu
Modified: 2017-06-19 11:51 CEST (History)
0 users

See Also:
Source RPM: perl-rt-authen-externalauth
CVE: CVE-2017-5361
Status comment:


Attachments

Description Zombie Ryushu 2017-06-19 10:47:32 CEST
It was discovered that RT::Authen::ExternalAuth, an external authentication module for Request Tracker, is vulnerable to timing side-channel attacks for user passwords. Only ExternalAuth in DBI (database) mode is vulnerable.
Zombie Ryushu 2017-06-19 10:48:43 CEST

CVE: (none) => CVE-2017-5361

Comment 1 David Walser 2017-06-19 11:51:46 CEST
We don't have this package.

Status: NEW => RESOLVED
Resolution: (none) => INVALID


Note You need to log in before you can comment on or make changes to this bug.