Login
Newsletter
Werbung

Sicherheit: Denial of Service in Swift
Aktuelle Meldungen Distributionen
Name: Denial of Service in Swift
ID: USN-2001-1
Distribution: Ubuntu
Plattformen: Ubuntu 12.04 LTS, Ubuntu 12.10, Ubuntu 13.04
Datum: Do, 24. Oktober 2013, 06:55
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4155
Applikationen: OpenStack

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============8998100722802107512==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="v1p8moCdal3PJsaAoU5CUfKLkqiP5hIGJ"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--v1p8moCdal3PJsaAoU5CUfKLkqiP5hIGJ
Content-Type: text/plain; charset=UTF-
Content-Transfer-Encoding: quoted-printable


==========================================================================
Ubuntu Security Notice USN-2001-1
October 23, 2013

swift vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS

Summary:

Swift could cause the system to crash if it received specially crafted
requests over the network.

Software Description:
- swift: OpenStack distributed virtual object store

Details:

Peter Portante discovered that Swift did not properly handle requests with
old X-Timestamp values. An authenticated attacker could exploit this to
cause a denial of service via disk consumption.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
python-swift 1.8.0-0ubuntu1.3

Ubuntu 12.10:
python-swift 1.7.4-0ubuntu2.3

Ubuntu 12.04 LTS:
python-swift 1.4.8-0ubuntu2.3

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2001-1
CVE-2013-4155

Package Information:
https://launchpad.net/ubuntu/+source/swift/1.8.0-0ubuntu1.3
https://launchpad.net/ubuntu/+source/swift/1.7.4-0ubuntu2.3
https://launchpad.net/ubuntu/+source/swift/1.4.8-0ubuntu2.3





--v1p8moCdal3PJsaAoU5CUfKLkqiP5hIGJ
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSaDSUAAoJEFHb3FjMVZVzN+sQAJVRjhexc+vVKV1A4h5quKxP
RQvPue6g82ZTDDI5dqRdeDiD6lsjR1x9hzmssbBtYEdcAFxB8N+wpw5zvLKxJddd
gL9HMdxemwrYSfC88r5Z8+virOcG22tKUMaMHhut3gz3u8WPUc4htOPzqTLPRC4E
3Hg5uw3++TNuyaBmPrGWYkV08cqBYNZbkX8diAGmYCc/LaRoggN44PHCScmqYYUI
qDQOJTl+Z9q/r73h46zIxjl0Gt5HD3vxHtDg4IcrFadj2JlcM/XlHea1T86X1KmT
LnAxA0OlwuQVkAk2L6R7BAu28vbUXxmo448SS7V1rcht0okqvRLeTuvBCUBz2q3X
rpFVvkg7bxBehOpEKV3o4gyHSM9Vxuz6Duw69DhiMkr6LNaxEU7akb+qUyOIowUd
aKKL/FzKW4cYsBuEBB6Nfv3UaHAyXS0IF+gPsTTF7yucwMI3BOxVTN0YtavkxVgv
pHsNOJr2gXHM9PTKaK2v0newAEF1bSOBF6kQ19LZlYOh4ShHWRdX8SjIN8h5Z0ut
lKMm3lK0nxKoIlG3Ebfya0VjXvVibyJsVFoqitubCe6KGVsBSgo1S4a+4gkhpCv8
4TjfiMUGIgYdd4h35auzPcdZsbljmv7TvevqeO1zXJj9FHBoxzBXBUVFYm9Q9mpT
J9lKHdMHM6Wjk41XjlsU
=RSCF
-----END PGP SIGNATURE-----

--v1p8moCdal3PJsaAoU5CUfKLkqiP5hIGJ--


--===============8998100722802107512==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============8998100722802107512==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung