Login
Newsletter
Werbung

Sicherheit: Mangelnde Rechteprüfung in OpenStack
Aktuelle Meldungen Distributionen
Name: Mangelnde Rechteprüfung in OpenStack
ID: USN-1564-1
Distribution: Ubuntu
Plattformen: Ubuntu 12.04 LTS
Datum: Do, 13. September 2012, 09:03
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4413
Applikationen: OpenStack

Originalnachricht


--===============4435723505732905170==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="82I3+IH0IqGh5yIs"
Content-Disposition: inline


--82I3+IH0IqGh5yIs
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-1564-1
September 13, 2012

keystone vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

OpenStack Keystone did not properly handle user role changes

Software Description:
- keystone: OpenStack identity service

Details:

Dolph Mathews discovered that when roles are granted and revoked to
users in Keystone, pre-existing tokens were not updated or invalidated
to take the new roles into account. An attacker could use this to
continue to access resources that have been revoked.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
keystone 2012.1+stable~20120824-a16a0ab9-0ubuntu2.2
python-keystone 2012.1+stable~20120824-a16a0ab9-0ubuntu2.2

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1564-1
CVE-2012-4413

Package Information:
https://launchpad.net/ubuntu/+source/keystone/2012.1+stable~20120824-a16a0ab9-0ubuntu2.2


--82I3+IH0IqGh5yIs
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAEBCgAGBQJQUXnMAAoJEC8Jno0AXoH0BQQP/2piRuWtDJ6S1xLOJu8pM0l/
2uMjPXQUDY412YeOngShqE8c34Z9ETOYgKhc3hHx+smENtx7Q/jeb7VfPMS4Fyw6
TTpk+8uuY0/s190fJbAsTKTzS4MztT2miFBda3zHgLS04JMWqdRhzA+aqaYiRVma
2q9mVZlxVrw1HAoYbmCMyhstm8wsOrMGqBMGSx6Rujv+pEt8k4skGyR7lGd6kNNw
aZiD27f1pZPiRcUTWID33IEvKyfQGK3mEzjmxOcr5HGrJ2g/DusL1zwXbHCnp9VM
lXqabwvkpibA26/V2+q+6sX5zF76f4kEbh0RAi+akkKc3bQJViha94Z66WJ2fXkJ
dghDQaUDQJsNI7xSsYd4ppw0JXaJOFK0iQeFUuVVBltQguYS4mGYX+NSysvXX4xE
MVMKCCNLGwVGaacdEduMxBNV/GJsnpAxR/hl2i0PRk8Xch64yRXobQtST0sKVZyf
7HkUakaIwB5LHMWHaU1w0Uw3tAaDBK0170GSKLtF17AU0+Fb5vLSBBDdFuC3HQqA
eSC1zNNyTSOqNzqWow35I39BotKi0pcpA1X0qKy2YBscTNmrbYKDW67Fk+IW85UP
0jl3CDU7X4VpnxGwMfqJ+qJmJSJzljN5fWiIii1WQGwavU/5vmyaEzralnr04LFR
Eill/n8BfF7z222NcZSx
=tB+N
-----END PGP SIGNATURE-----

--82I3+IH0IqGh5yIs--


--===============4435723505732905170==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============4435723505732905170==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung