Red Hat 7 RHSA-2000:094-01 critical: cyrus-sasl authorization error
Summary
Summary
An error existed in the authorization checks in the version of cyrus-saslshipped with Red Hat Linux 7. Due to this bug, users who had beensuccessfully authenticated could be allowed access to resources even if thesystem had been configured to deny these users access.Versions of cyrus-sasl included in previous releases of Red Hat Power Toolsdid not implement this function and are not affected by this bug.
Solution
For each RPM for your particular architecture, run:
rpm -Fvh [filename]
where filename is the name of the RPM.
5. Bug IDs fixed ( for more info):
18968 - cyrus-sasl-1.5.24 is not the "real" 1.5.24
6. RPMs required:
Red Hat Linux 7.0:
i386:
sources:
7. Verification:
MD5 sum Package Name
6a969df3702bb670ae65cf0824146472 7.0/SRPMS/cyrus-sasl-1.5.24-11.src.rpm
59aaec92c60ddaed257bd581d976055b 7.0/i386/cyrus-sasl-1.5.24-11.i386.rpm
These packages are GPG signed by Red Hat, Inc. for security. Our key
is available at:
You can verify each package with the following command:
rpm --checksig
If you only wish to verify that each package has not been corrupted or
tampered with, examine only the md5sum with the following command:
rpm --checksig --nogpg
References
N/A Copyright(c) 2000 Red Hat, Inc. `
Package List
Topic
Topic
Updated cyrus-sasl packages are now available for Red Hat Linux 7.
Relevant Releases Architectures
Red Hat Linux 7.0 - i386
Bugs Fixed