SB2017050517 - Fedora 24 update for radicale
Published: May 5, 2017 Updated: April 24, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Race condition (CVE-ID: CVE-2017-8342)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method.
Remediation
Install update from vendor's website.