[Pkg-freeipa-devel] [PATCH 0076] Ensure that a password exists after OTP validation

Alexander Bokovoy abokovoy at redhat.com
Wed Nov 5 20:22:16 UTC 2014


On Wed, 05 Nov 2014, Nathaniel McCallum wrote:
>Before this patch users could log in using only the OTP value. This
>arose because ipapwd_authentication() successfully determined that
>an empty password was invalid, but 389 itself would see this as an
>anonymous bind. An anonymous bind would never even get this far in
>this code, so we simply deny requests with empty passwords.
>
>This patch resolves CVE-2014-7828.
>
>https://fedorahosted.org/freeipa/ticket/4690
ACK.

We need to do release for 4.0 and 4.1 first thing tomorrow.
A possible workaround is to disable 2FA for users in mean time.


-- 
/ Alexander Bokovoy



More information about the Pkg-freeipa-devel mailing list