|
|
| |
|
| |
python-pyrad: predictable password hashing
| Package(s): | python-pyrad |
CVE #(s): | CVE-2013-0294
|
| Created: | September 16, 2013 |
Updated: | September 18, 2013 |
| Description: |
From the Red Hat bugzilla:
Nathaniel McCallum reported that pyrad was using Python's random module in a number of places to generate pseudo-random data. In the case of the authenticator data, it was being used to secure a password sent over the wire. Because Python's random module is not really suited for this purpose (not random enough), it could lead to password hashing that may be predictable. |
| Alerts: |
|
( Log in to post comments)
|
|
|