_______________________________________________________________________
Package : apache-mod_auth_shadow
Date : April 18, 2010
Affected: 2008.0, 2009.1, 2010.0, Corporate 4.0
_______________________________________________________________________
Problem Description:
A vulnerability has been found and corrected in apache-mod_auth_shadow:
A race condition was found in the way mod_auth_shadow used an external
helper binary to validate user credentials (username / password
pairs). A remote attacker could use this flaw to bypass intended
access restrictions, resulting in ability to view and potentially
alter resources, which should be otherwise protected by authentication
(CVE-2010-1151).
Packages for 2008.0 are provided for Corporate Desktop 2008.0
customers.
The updated packages have been patched to correct this issue.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2010-1151
https://bugzilla.redhat.com/show_bug.cgi?id=578168
_______________________________________________________________________