lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Mon, 10 Jul 2017 11:26:24 -0700 From: Sailesh Mukil <sailesh@...che.org> To: bugtraq@...urityfocus.com Subject: CVE-2017-5640 Apache Impala (incubating) Information Disclosure CVE-2017-5640 Apache Impala (incubating) Information Disclosure Severity: High Versions Affected: Apache Impala (incubating) 2.7.0 to 2.8.0 Description: It was noticed that a malicious process impersonating an Impala daemon could cause Impala daemons to skip authentication checks when Kerberos is enabled (but TLS is not). If the malicious server responds with ‘COMPLETE’ before the SASL handshake has completed, the client will consider the handshake as completed even though no exchange of credentials has happened. Mitigation: Users of the affected versions should apply the following mitigation: Upgrade to Apache Impala (incubating) 2.9.0 Credit: This issue was identified by the Cloudera Security team. References: https://issues.apache.org/jira/browse/IMPALA-5005
Powered by blists - more mailing lists