LWN.net Logo

python-pyrad: predictable password hashing

Package(s):python-pyrad CVE #(s):CVE-2013-0294
Created:September 16, 2013 Updated:September 18, 2013
Description: From the Red Hat bugzilla:

Nathaniel McCallum reported that pyrad was using Python's random module in a number of places to generate pseudo-random data. In the case of the authenticator data, it was being used to secure a password sent over the wire. Because Python's random module is not really suited for this purpose (not random enough), it could lead to password hashing that may be predictable.

Alerts:
Fedora FEDORA-2013-15891 2013-09-15
Fedora FEDORA-2013-15877 2013-09-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds