LWN.net Logo

luci: authentication bypass

Package(s):luci CVE #(s):CVE-2010-3852
Created:November 3, 2010 Updated:November 5, 2010
Description: From the Red Hat bugzilla:

A security flaw was found in the way Luci administration application processed ticket cookies. A remote attacker, with certain knowledge of running Luci instance environment details could use this flaw to bypass standard Luci authentication mechanism (access resources which should be otherwise protected by authentication).

Alerts:
Fedora FEDORA-2010-16848 2010-10-28
Fedora FEDORA-2010-16601 2010-10-22
Fedora FEDORA-2010-16617 2010-10-22

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds