Preisgabe von Informationen in OpenStack (Aktualisierung)
ID: | USN-2311-2 |
Distribution: | Ubuntu |
Plattformen: | Ubuntu 14.04 LTS |
Datum: | Fr, 22. August 2014, 08:42 |
Referenzen: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4615 |
Applikationen: | OpenStack |
Update von: | Preisgabe von Informationen in pyCADF |
Originalnachricht |
|
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============3380989471284024138== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="AphrcIp4fcfTSjxL4QDSHTI4jGqw5lVbw" This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --AphrcIp4fcfTSjxL4QDSHTI4jGqw5lVbw Content-Type: text/plain; charset=utf- Content-Transfer-Encoding: quoted-printable ========================================================================== Ubuntu Security Notice USN-2311-2 August 21, 2014 ceilometer vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: OpenStack Ceilometer could be made to expose sensitive information. Software Description: - ceilometer: OpenStack Telemetry service Details: USN-2311-1 fixed vulnerabilities in pyCADF. This update provides the corresponding updates for OpenStack Ceilometer. Original advisory details: Zhi Kun Liu discovered that pyCADF incorrectly filtered certain tokens. An attacker could possibly use this issue to obtain authentication tokens used in REST requests. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: ceilometer-common 2014.1.2-0ubuntu1.1 In general, a standard system update will make all the necessary changes. References: http://www.ubuntu.com/usn/usn-2311-2 http://www.ubuntu.com/usn/usn-2311-1 CVE-2014-4615 Package Information: https://launchpad.net/ubuntu/+source/ceilometer/2014.1.2-0ubuntu1.1 --AphrcIp4fcfTSjxL4QDSHTI4jGqw5lVbw Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJT9lCJAAoJEFHb3FjMVZVzpJMP/1vlSUeC5WC8jHpHq+zqSgKD WHf5LhqRz/c5OudMoHBHh5WvSYYfo72/nO4WyPYE+nZGAR+Kgf67AgSatkl5HEHx mSxGeQ3dCDTyzthLWGmhfekHe94X9tfLolSgcVrTpPhvxhZ3p3ClIf4UevfMY8EM SFL5/KchTg1iif3hMUsT8jW3dU3Injid1XvX0YAv4pLhv6JIfkxZaf+4vgIQhtaP csblaUNosS45nuYJXlowP51P5DFWv0+6MnVc/OyZ3LI74Cbo/cql5mEtNxjzvxzW 10H20xYEkjSsOH7hXhzaZQ2+2GbesfUVIpXUnN55oaBWWGn8/pPYx040fLkG1RxA PogADDQyWmzFv+z62wIrFhKmn23mtiC1ppb4x7QB2jDTPOloaukusNNZtVdYhtaS smrPMXsXCtED3JW28YJIgIwCoA/Y8QBhvFUPDBwK7k1gwn6z06lvqn0ZdTUKPsD/ F2AEsnPbEBn/w1CkvCiV13nPXCdqu7aBg/HXxmpOWFX2OewJ85QoUM8mWCoxlGqR bhZWN3R0vpUe7oO/tKIbviw0eWyN9EqCcEfz2+3WfXQ/Au9NUZ+yd6z+lqwPrHsQ eBY8RcgLJVgSCMXvaP6dORcObPGoPmv2+KGYorqRPusUl8Yn0Wn9Yl7KHxS7AIie 9IAElFHy9nGY1x/pYNkr =Cx84 -----END PGP SIGNATURE----- --AphrcIp4fcfTSjxL4QDSHTI4jGqw5lVbw-- --===============3380989471284024138== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce --===============3380989471284024138==-- |