Login
Newsletter
Werbung

Sicherheit: Cross-Site Scripting in Horizon
Aktuelle Meldungen Distributionen
Name: Cross-Site Scripting in Horizon
ID: USN-1439-1
Distribution: Ubuntu
Plattformen: Ubuntu 12.04 LTS
Datum: Mo, 7. Mai 2012, 18:47
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2094
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2144
Applikationen: Django Horizon

Originalnachricht


--===============8964891308973077227==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-L1lWW6Yb8Gly3CrefxXC"


--=-L1lWW6Yb8Gly3CrefxXC
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1439-1
May 07, 2012

horizon vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

Horizon could be made to expose sensitive information over the network.

Software Description:
- horizon: Web interface for OpenStack cloud infrastructure

Details:

Matthias Weckbecker discovered a cross-site scripting (XSS) vulnerability
in Horizon via the log viewer refrash mechanism. If a user were tricked
into viewing a specially crafted log message, a remote attacker could
exploit this to modify the contents or steal confidential data within the
same domain. (CVE-2012-2094)

Thomas Biege discovered a session fixation vulnerability in Horizon. An
attacker could exploit this to potentially allow access to unauthorized
information and capabilities. (CVE-2012-2144)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
python-django-horizon 2012.1-0ubuntu8.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1439-1
CVE-2012-2094, CVE-2012-2144

Package Information:
https://launchpad.net/ubuntu/+source/horizon/2012.1-0ubuntu8.1



--Õ1lWW6Yb8Gly3CrefxXC
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJPp9iyAAoJEFHb3FjMVZVzoUcP/0ys6x0aJ39oRgtybuN3mWf+
EYMCc9S1+PzMddyW1RlPd+ioEvtkJPH5yL3s7BITLTVivAQbTY7vjTUf5+W84D6K
dkFOFZXrIiZXAXyCRuVDOSO7oUE0Ck5aRJYKZVqpANYrHvLguTc7bRTXzk6YorJJ
m7aXx7tMadgqmA+N3X0NeuJ8b8vjwGUlNXt0+zuGtBZ3b3DjrRKKzoAwqfSdR7UC
6jARNUZ36p2U0nXGZT5CjgMr7ft29ZM1l2yaBkD0cf3H0b9RgvkFmwt5y+2Dc5DR
j/XNzcgPcX8cQzsmVXMnaqTshkT0FY9FgS9ZExQynQ+dwpt9POKN66ZOQX7cQY8Y
QD3GZIOdAtdfLyEuJcvhRPMAliZqysul2hS9PIxIwFrEhDbwl++GwJtNlX008XIq
QjOqFMdH9yDCNrre7+hEJfOIjkOsF78jxDGiAQBYunQsVpwFt0keijKEKsrOkCd0
UQ1Rf8YlX1FiTdfx4k9SZfGmERCsgdEYC4Pk/n8ZblOL8GOq5S3eAMsx2aDBMqbS
kCRhFCLkC7lZ/OjLgvAAI9LmNyjdrqLxSu+TWuFpOM5wkQw8NdNjceKWGobXEApO
mCsKW7QcIDHOC/oDxPAzCgWzBwQpJw+YGkkybA59jwgNKq3Z1G7KNv92mUswaaoX
xlfO7q0T6gRVkjy7/1mp
=o3rF
-----END PGP SIGNATURE-----

--=-L1lWW6Yb8Gly3CrefxXC--



--===============8964891308973077227==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============8964891308973077227==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung