| Summary: | CVE-2011-4973 mod_nss: FakeBasicAuth authentication bypass | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Tomas Hoger <thoger> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | alee, awnuk, cfu, dpal, jkurik, jmagne, mharmsen, nkinder, pfrields, rcritten, rmeggins, thoger, vkrizan |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2013-11-14 21:52:01 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Bug Depends On: | 702437, 749402, 1017675, 1022921 | ||
| Bug Blocks: | 830846 | ||
|
Description
Tomas Hoger
2013-10-09 12:26:46 UTC
It should be noted that after the fix, any htpasswd file that was created for use with older mod_nss version (i.e. file that only contains CN for user name) need to be changed to use full DN. This is required to both make authentication work for valid users authenticating using client certificates, as well as to address the authentication bypass. Created mod_nss tracking bugs for this issue: Affects: fedora-all [bug 1017675] |