Bug 841175 - (CVE-2012-3416) CVE-2012-3416 condor: host based authentication does not implement forward-confirmed reverse dns
CVE-2012-3416 condor: host based authentication does not implement forward-co...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
Unspecified Unspecified
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20120814,repo...
: Security
Depends On: 841177 848145
Blocks: 841432
  Show dependency treegraph
 
Reported: 2012-07-18 06:41 EDT by Matthew Farrellee
Modified: 2012-10-03 10:43 EDT (History)
9 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
: 841177 (view as bug list)
Environment:
Last Closed: 2012-08-14 14:27:05 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Condor 3131 None None None 2012-07-18 06:41:20 EDT

  None (edit)
Comment 6 Vincent Danen 2012-08-08 16:26:04 EDT
Condor installations that rely solely upon host-based authentication are vulnerable to an attacker who controls an IP, its reverse-DNS entry and has knowledge of a target site's security configuration. With this control and knowledge, the attacker can bypass the target site's host-based authentication and be authorized to perform privileged actions (i.e. actions requiring ALLOW_ADMINISTRATOR or ALLOW_WRITE). Condor deployments using host-based authentication that contain no hostnames (IPs or IP globs only) or use authentication stronger than host-based are not vulnerable.
Comment 10 Vincent Danen 2012-08-10 15:09:07 EDT
Acknowledgements:

Red Hat would like to thank Ken Hahn and Dan Bradley for reporting this issue.
Comment 14 errata-xmlrpc 2012-08-14 13:58:18 EDT
This issue has been addressed in following products:

  MRG for RHEL-6 v.2

Via RHSA-2012:1169 https://rhn.redhat.com/errata/RHSA-2012-1169.html
Comment 15 errata-xmlrpc 2012-08-14 13:58:51 EDT
This issue has been addressed in following products:

  MRG for RHEL-5 v. 2

Via RHSA-2012:1168 https://rhn.redhat.com/errata/RHSA-2012-1168.html
Comment 16 Vincent Danen 2012-08-14 14:26:26 EDT
Created condor tracking bugs for this issue

Affects: fedora-all [bug 848145]

Note You need to log in before you can comment on or make changes to this bug.