Login
Newsletter
Werbung

Sicherheit: Mangelnde Rechteprüfung in python-keystoneclient
Aktuelle Meldungen Distributionen
Name: Mangelnde Rechteprüfung in python-keystoneclient
ID: USN-1851-1
Distribution: Ubuntu
Plattformen: Ubuntu 13.04
Datum: Di, 4. Juni 2013, 10:39
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2104
https://launchpad.net/ubuntu/+source/python-keystoneclient/1:0.2.3-0ubuntu2.2
Applikationen: OpenStack

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--===============1977801480755231829==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="------------enigDCCF4EB1A9B39613E4175D59"

This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--------------enigDCCF4EB1A9B39613E4175D59
Content-Type: text/plain; charset=ISO-8859-
Content-Transfer-Encoding: quoted-printable


==========================================================================
Ubuntu Security Notice USN-1851-1
June 03, 2013

python-keystoneclient vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04

Summary:

The python client library for Keystone did not properly verify expired PKI
tokens.

Software Description:
- python-keystoneclient: Client library for OpenStack Identity API

Details:

Eoghan Glynn and Alex Meade discovered that python-keystoneclient did not
properly perform expiry checks for the PKI tokens used in Keystone. If
Keystone were setup to use PKI tokens (the default in Ubuntu 13.04), a
previously authenticated user could continue to use a PKI token for longer
than intended.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
python-keystoneclient 1:0.2.3-0ubuntu2.2

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1851-1
CVE-2013-2104

Package Information:

https://launchpad.net/ubuntu/+source/python-keystoneclient/1:0.2.3-0ubuntu2.2





--------------enigDCCF4EB1A9B39613E4175D59
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with undefined - http://www.enigmail.net/

iQIcBAEBCgAGBQJRrV43AAoJEFHb3FjMVZVzHdoP+wVkaLX6gOfSruyRxty5SsAO
zD+BX7quWo/GQycAfZwaj806vsRLyS0e6mOjCaGEt7lK/dFbnUR43NzJOJsyJ60y
7lS/09qu7InCjuHj87nyDOJXiv9NRB1tVvSUbF7yvT1mAclM/AOBmLPnV4Vft7pS
C5ACkFqTR4zWymvVhQsYrUJaZhsqATYto76jIZ4fKj5IQ+3brZmJk23rA7358GbU
xr7d3NxcU8NK9Qfrcty+u5EwRsgiA4Gwb05/mdLsL+keqtqDJl+ODBMVOElTEW3L
YXmg6Hjvx2gs5zrQxEOn0fSSK7MMGJBjCADVz5iNRRinJkZR5FlobORcNezNm5eA
n66Dmz/zfNdAuiFMPaiyaNCUuHi7+CEW/2rtbKqN0ACE1NzpLOyUjdvpopXpy9B3
HRxyUszW//WFTUcCAOGLPxKDj+LOHe7gks37a2u2cHldeBoTsu2fT0A7S8Jt3uPB
f+tohwBg5QNiT8DkCNc9neJHUgz/stxlzJN24CIakt1EoGS3vcBpmxXPOZjKc6wE
/LMlb0xmVMDnKAmFsXnNAitG0mt/lamScHViaDl3Phsx3WWwjOWGXjTwkzM9AAEV
+TK5dC+xC+3v3n84XnlaOyZgzz65gyXN/7a3yLra8dfyslwixg2U4ByijdVcFHCZ
nCbFbdA8ylr0Q7hGnHcK
=TZUG
-----END PGP SIGNATURE-----

--------------enigDCCF4EB1A9B39613E4175D59--


--===============1977801480755231829==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============1977801480755231829==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung