Categories: Open SourceSoftware

Fedora Linux Account System Patched For Serious Flaw

Fedora Linux and Red Hat are investigating the potential impact of a major vulnerability that was first disclosed Aug. 8.

The Fedora Account System (FAS), which provides user information management for Fedora, had a vulnerability identified as CVE-2016-1000038, which could have enabled an unauthorized user to make changes to the system. Fedora is Red Hat’s community Linux effort.

“This flaw would allow a specifically formatted HTTP request to be authenticated as any requested user,” Paul Frields, engineering manager at Red Hat, wrote in a mailing list message. “If the authenticated user had appropriate privileges, the attacker would then be able to add, edit, or remove user or group information.”

Red Hat Linux Security

The vulnerability has already been patched in the production version of FAS, Frields said, adding that the infrastructure team is in the process of investigating the issue to see if the vulnerability was ever exploited.

That said, the early indication is that the flaw was not exploited and no Fedora accounts or information was altered because of it.

Going a step further, Frields wrote that at this point the Fedora project team is confident that package content in the Fedora product is not affected by this flaw. Typically, when there is some type of administrative account vulnerability, there is a need to reset user passwords, but that’s not happening at this point for any FAS users.

This isn’t the first time the Fedora Linux project has had a security issue with its infrastructure. Back in 2008, both Fedora and Red Hat Enterprise Linux suffered a breach in the back-end infrastructure. That breach resulted in a systems outage for Red Hat and Fedora infrastructure that lasted three weeks, while the investigation and cleanup was ongoing. Despite that breach in 2008, the Fedora 10 release of that same year still came out roughly on schedule.

More recently, multiple Linux vendors in 2016 have reacted promptly to security vulnerabilities that have been reported.  In February, there was a breach of the Linux Mint distribution and its user forums. In July, 2 million usernames and emails of Ubuntu Linux users were exposed after a breach resulting from unpatched forum software.

Originally published on eWeek

What do you know about Linux? Take our quiz!

Sean Michael Kerner

Sean Michael Kerner is a senior editor at eWeek and contributor to TechWeek

Recent Posts

Microsoft Beats Expectations Thanks To AI Investments

Customer adoption of AI services embedded in cloud services continues to deliver results for Microsoft,…

13 hours ago

Google Delays Removal Of Third-Party Cookies, Again

For third time Google delays phase-out of third-party Chrome cookies after pushback from industry and…

1 day ago