|
|
| |
An error existed in the authorization checks in the version of cyrus-sasl shipped with Red Hat Linux 7. Due to this bug, users who have been successfully authenticated could be allowed access to resources even if the system had been configured to deny these users' access.
Versions of cyrus-sasl included in previous releases of Red Hat Power Tools did not implement this function and are not affected by this bug. |
| |
Credit:
The information has been provided by RedHat Bugzilla.
|
| |
Vulnerable systems:
Red Hat Linux 7.0 - i386
Solution:
For each RPM for your particular architecture, run:
rpm -Fvh [filename]
Where filename is the name of the RPM.
Patch:
Red Hat Linux 7.0:
i386:
ftp://updates.redhat.com/7.0/i386/cyrus-sasl-1.5.24-11.i386.rpm
Sources:
ftp://updates.redhat.com/7.0/SRPMS/cyrus-sasl-1.5.24-11.src.rpm
|
|
|