Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in OpenStack
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in OpenStack
ID: USN-3451-1
Distribution: Ubuntu
Plattformen: Ubuntu 14.04 LTS
Datum: Mi, 11. Oktober 2017, 18:49
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0737
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0738
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5223
Applikationen: OpenStack

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============5880726748064693797==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="vHb72XPpSs05Bx3JRFTEoisIOhlhM5vDp"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--vHb72XPpSs05Bx3JRFTEoisIOhlhM5vDp
Content-Type: multipart/mixed;
boundary="5gVOsWDqJ888TqnIFasI2f65s3TGxNTsl";
protected-headers="v1"
From: Marc Deslauriers <marc.deslauriers@canonical.com>
Reply-To: Ubuntu Security <security@ubuntu.com>
To: "ubuntu-security-announce@lists.ubuntu.com"
<ubuntu-security-announce@lists.ubuntu.com>
Message-ID: <7b0eeecf-3eea-e287-677c-92ebfe09fd50@canonical.com>
Subject: [USN-3451-1] OpenStack Swift vulnerabilities

--5gVOsWDqJ888TqnIFasI2f65s3TGxNTsl
Content-Type: text/plain; charset=utf-8
Content-Language: en-C
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-3451-1
October 11, 2017

swift vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in OpenStack Swift.

Software Description:
- swift: OpenStack distributed virtual object store

Details:

It was discovered that OpenStack Swift incorrectly handled tempurls. A
remote authenticated user in possession of a tempurl key authorized for PUT
could retrieve other objects in the same Swift account. (CVE-2015-5223)

Romain Le Disez and Örjan Persson discovered that OpenStack Swift
incorrectly closed client connections. A remote attacker could possibly use
this issue to consume resources, resulting in a denial of service.
(CVE-2016-0737, CVE-2016-0738)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
python-swift 1.13.1-0ubuntu1.5
swift 1.13.1-0ubuntu1.5

In general, a standard system update will make all the necessary changes.

References:
https://www.ubuntu.com/usn/usn-3451-1
CVE-2015-5223, CVE-2016-0737, CVE-2016-0738

Package Information:
https://launchpad.net/ubuntu/+source/swift/1.13.1-0ubuntu1.5



--5gVOsWDqJ888TqnIFasI2f65s3TGxNTsl--

--vHb72XPpSs05Bx3JRFTEoisIOhlhM5vDp
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJZ3hulAAoJEGVp2FWnRL6TjKUP/3nEXlhfMNf+QkNxYTCMu8tx
+O9RlIINsGjibOE/WF5cclMrs0J6m6gTBeO8+89jzXOQw1Jm1+N1gMAteWRN8Eti
up2Q3KzYhidgorl7MDfjjOeAlkXSA5K0tIg3pyR8j2g4HHhCKkn/2ty1V3HzPGxM
73pKqI/0sjzBQLLrIJrBG9l1cbZGiWjn7Vs1WZYaVf30Pbuhfzo3R9+vu4wGFvpu
HlFMcaJaQAlgGK7aWU/StIOIjJ+s9LuwWB4deAc8bfMoTk1eqRDWgPWzWVV1tEMl
ZqtfdZp3KzIqe/Ejy1vpxP19VBzZvixHDce2ZY+yBsjOpKvgAPVfkeoT6jUswDyd
rEwSGTJpRrq3wMJqDQjR23HlF4DWuR3eyGCyAMATf4NdEsfrlobcSUijDcZ6eZGp
62Kih9S5A225DxHUygxIot7OhkTg6SHPqt+ArbWY88h4qAeB3WfvoP9SSula5q6U
jn/Cc+1WJbR61pQJGs9upB2Cjh2n4jFIASOccG61aduZalNkpDVjCwkTcGerO7Ct
GN6E775zAUiqJnhV3OgyoUaLwUAe1a2owUHR4mFBQiKlvmkuU+xtBLD7rsvX57eM
UxIRb/QE5haABWo6n2WYih5TBI5PlrU08D1Lr9SnFITZpYdqrige0OQCzs0bkOWu
UbEiL7+VLOI2u1xGSAyt
=HtrY
-----END PGP SIGNATURE-----

--vHb72XPpSs05Bx3JRFTEoisIOhlhM5vDp--


--===============5880726748064693797==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============5880726748064693797==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung