Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in python-keystoneclient
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in python-keystoneclient
ID: FEDORA-2013-14302
Distribution: Fedora
Plattformen: Fedora 19
Datum: Do, 15. August 2013, 08:54
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2013
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2104
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2166
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2167
Applikationen: OpenStack

Originalnachricht

Name        : python-keystoneclient
Product : Fedora 19
Version : 0.2.3
Release : 7.fc19
URL : http://pypi.python.org/pypi/python-keystoneclient
Summary : Client library for OpenStack Identity API
Description :
Client library and command line utility for interacting with Openstack
Identity API.

-------------------------------------------------------------------------------
-
Update Information:

Selective backports from stable/grizzly:
* Ec2Signer: Initial support for v4 signature verification.
* Allow signature verification for older boto versions.
* Default signing_dir to secure temp dir.
* Fix memcache encryption middleware. (CVE-2013-2166, CVE-2013-2167)
* Check token expiry. (CVE-2013-2104)
* Allow secure user password update. (CVE-2013-2013)

-------------------------------------------------------------------------------
-
ChangeLog:

* Mon Aug 5 2013 Jakub Ruzicka <jruzicka@redhat.com> 0.2.3-7
- Ec2Signer: Allow signature verification for older boto versions. (#984752)
* Mon Jul 29 2013 Jakub Ruzicka <jruzicka@redhat.com> 0.2.3-6
- Allow secure user password update. (CVE-2013-2013)
* Thu Jul 25 2013 Jakub Ruzicka <jruzicka@redhat.com> 0.2.3-5
- Ec2Signer: Initial support for v4 signature verification.
- Default signing_dir to secure temp dir.
- Fix memcache encryption middleware. (CVE-2013-2166, CVE-2013-2167)
* Tue May 28 2013 Jakub Ruzicka <jruzicka@redhat.com> 0.2.3-4
- Check token expiry. (CVE-2013-2104)
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #974271 - CVE-2013-2166 CVE-2013-2167 python-keystoneclient:
middleware memcache encryption and signing bypass
https://bugzilla.redhat.com/show_bug.cgi?id=974271
[ 2 ] Bug #965852 - CVE-2013-2104 OpenStack Keystone: Missing expiration
check in Keystone PKI token validation
https://bugzilla.redhat.com/show_bug.cgi?id=965852
-------------------------------------------------------------------------------
-

This update can be installed with the "yum" update program. Use
su -c 'yum update python-keystoneclient' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Pro-Linux
Traut euch!
Neue Nachrichten
Werbung