Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 953910 - (CVE-2013-1977) CVE-2013-1977 openstack-keystone: Insecure management of LDAP and admin_token configuration file values
CVE-2013-1977 openstack-keystone: Insecure management of LDAP and admin_token...
Status: CLOSED NOTABUG
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,public=20130412,reported=2...
: Security
Depends On:
Blocks: 953921
  Show dependency treegraph
 
Reported: 2013-04-19 09:51 EDT by Jan Lieskovsky
Modified: 2015-07-31 03:03 EDT (History)
11 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2013-08-08 23:55:24 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Jan Lieskovsky 2013-04-19 09:51:10 EDT
A security flaw was found in the way Openstack Keystone (previously) performed management of LDAP password and admin_token Keystone daemon configuration file values. A local attacker could use this flaw to obtain sensitive information.

References:
[1] https://bugs.launchpad.net/keystone/+bug/1168252
[2] http://www.openwall.com/lists/oss-security/2013/04/19/2

Relevant upstream patch (Gerrit form):
[3] https://review.openstack.org/#/c/26826/
Comment 2 Jan Lieskovsky 2013-04-24 03:46:16 EDT
Further CVE-2013-1977 vs CVE-2013-2006 ids disambiguation:
  https://bugs.launchpad.net/devstack/+bug/1168252/comments/7
Comment 3 Vincent Danen 2013-05-09 13:49:13 EDT
CVE-2013-1977 does not affect our installer, as it was hardened previously and has 0600 permissions, as noted on oss-sec:

http://seclists.org/oss-sec/2013/q2/126

Statement:

Not vulnerable.  This issue did not affect the version of openstack-keystone as shipped with Red Hat OpenStack Folsom.

Note You need to log in before you can comment on or make changes to this bug.