Bug 502250 (CVE-2009-1769) - CVE-2009-1769 OCS Inventory NG: Authentication result varies for existent and non-existent users
Summary: CVE-2009-1769 OCS Inventory NG: Authentication result varies for existent and...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2009-1769
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL: http://www.securityfocus.com/bid/3502...
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-05-22 19:28 UTC by Jan Lieskovsky
Modified: 2019-09-29 12:30 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2009-06-16 06:57:05 UTC


Attachments (Terms of Use)

Description Jan Lieskovsky 2009-05-22 19:28:53 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-1769 to
the following vulnerability:

The web interface in OCS Inventory NG 1.01 generates different error
messages depending on whether a username is valid, which allows remote
attackers to enumerate valid usernames. 

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1769
http://www.ocsinventory-ng.org/index.php?mact=News,cntnt01,detail,0&cntnt01articleid=133&cntnt01returnid=69
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=529344
http://www.securityfocus.com/bid/35023
http://secunia.com/advisories/35157

Comment 1 Fedora Update System 2009-05-30 18:55:41 UTC
ocsinventory-1.02.1-1.fc11 has been submitted as an update for Fedora 11.
http://admin.fedoraproject.org/updates/ocsinventory-1.02.1-1.fc11

Comment 2 Fedora Update System 2009-05-30 18:56:40 UTC
ocsinventory-1.02.1-1.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/ocsinventory-1.02.1-1.fc10

Comment 3 Fedora Update System 2009-05-30 18:57:05 UTC
ocsinventory-1.02.1-1.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/ocsinventory-1.02.1-1.fc9

Comment 4 Fedora Update System 2009-06-02 14:28:03 UTC
ocsinventory-1.02.1-1.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 5 Fedora Update System 2009-06-02 14:28:47 UTC
ocsinventory-1.02.1-1.fc11 has been pushed to the Fedora 11 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2009-06-02 14:29:15 UTC
ocsinventory-1.02.1-1.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.