Bug 502250 (CVE-2009-1769)

Summary: CVE-2009-1769 OCS Inventory NG: Authentication result varies for existent and non-existent users
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: fedora
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
URL: http://www.securityfocus.com/bid/35023/discuss
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2009-06-16 06:57:05 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Jan Lieskovsky 2009-05-22 19:28:53 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-1769 to
the following vulnerability:

The web interface in OCS Inventory NG 1.01 generates different error
messages depending on whether a username is valid, which allows remote
attackers to enumerate valid usernames. 

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1769
http://www.ocsinventory-ng.org/index.php?mact=News,cntnt01,detail,0&cntnt01articleid=133&cntnt01returnid=69
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=529344
http://www.securityfocus.com/bid/35023
http://secunia.com/advisories/35157

Comment 1 Fedora Update System 2009-05-30 18:55:41 UTC
ocsinventory-1.02.1-1.fc11 has been submitted as an update for Fedora 11.
http://admin.fedoraproject.org/updates/ocsinventory-1.02.1-1.fc11

Comment 2 Fedora Update System 2009-05-30 18:56:40 UTC
ocsinventory-1.02.1-1.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/ocsinventory-1.02.1-1.fc10

Comment 3 Fedora Update System 2009-05-30 18:57:05 UTC
ocsinventory-1.02.1-1.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/ocsinventory-1.02.1-1.fc9

Comment 4 Fedora Update System 2009-06-02 14:28:03 UTC
ocsinventory-1.02.1-1.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 5 Fedora Update System 2009-06-02 14:28:47 UTC
ocsinventory-1.02.1-1.fc11 has been pushed to the Fedora 11 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2009-06-02 14:29:15 UTC
ocsinventory-1.02.1-1.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.