drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mangelnde Rechteprüfung in OpenStack
Name: |
Mangelnde Rechteprüfung in OpenStack |
|
ID: |
USN-1564-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 12.04 LTS |
|
Datum: |
Do, 13. September 2012, 09:03 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4413 |
|
Applikationen: |
OpenStack |
|
Originalnachricht |
--===============4435723505732905170== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="82I3+IH0IqGh5yIs" Content-Disposition: inline
--82I3+IH0IqGh5yIs Content-Type: text/plain; charset=us-ascii Content-Disposition: inline
========================================================================== Ubuntu Security Notice USN-1564-1 September 13, 2012
keystone vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
OpenStack Keystone did not properly handle user role changes
Software Description: - keystone: OpenStack identity service
Details:
Dolph Mathews discovered that when roles are granted and revoked to users in Keystone, pre-existing tokens were not updated or invalidated to take the new roles into account. An attacker could use this to continue to access resources that have been revoked.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 12.04 LTS: keystone 2012.1+stable~20120824-a16a0ab9-0ubuntu2.2 python-keystone 2012.1+stable~20120824-a16a0ab9-0ubuntu2.2
In general, a standard system update will make all the necessary changes.
References: http://www.ubuntu.com/usn/usn-1564-1 CVE-2012-4413
Package Information: https://launchpad.net/ubuntu/+source/keystone/2012.1+stable~20120824-a16a0ab9-0ubuntu2.2
--82I3+IH0IqGh5yIs Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux)
iQIcBAEBCgAGBQJQUXnMAAoJEC8Jno0AXoH0BQQP/2piRuWtDJ6S1xLOJu8pM0l/ 2uMjPXQUDY412YeOngShqE8c34Z9ETOYgKhc3hHx+smENtx7Q/jeb7VfPMS4Fyw6 TTpk+8uuY0/s190fJbAsTKTzS4MztT2miFBda3zHgLS04JMWqdRhzA+aqaYiRVma 2q9mVZlxVrw1HAoYbmCMyhstm8wsOrMGqBMGSx6Rujv+pEt8k4skGyR7lGd6kNNw aZiD27f1pZPiRcUTWID33IEvKyfQGK3mEzjmxOcr5HGrJ2g/DusL1zwXbHCnp9VM lXqabwvkpibA26/V2+q+6sX5zF76f4kEbh0RAi+akkKc3bQJViha94Z66WJ2fXkJ dghDQaUDQJsNI7xSsYd4ppw0JXaJOFK0iQeFUuVVBltQguYS4mGYX+NSysvXX4xE MVMKCCNLGwVGaacdEduMxBNV/GJsnpAxR/hl2i0PRk8Xch64yRXobQtST0sKVZyf 7HkUakaIwB5LHMWHaU1w0Uw3tAaDBK0170GSKLtF17AU0+Fb5vLSBBDdFuC3HQqA eSC1zNNyTSOqNzqWow35I39BotKi0pcpA1X0qKy2YBscTNmrbYKDW67Fk+IW85UP 0jl3CDU7X4VpnxGwMfqJ+qJmJSJzljN5fWiIii1WQGwavU/5vmyaEzralnr04LFR Eill/n8BfF7z222NcZSx =tB+N -----END PGP SIGNATURE-----
--82I3+IH0IqGh5yIs--
--===============4435723505732905170== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
--===============4435723505732905170==--
|
|
|
|