Login
Newsletter
Werbung

Sicherheit: Preisgabe von Informationen in pyCADF
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in pyCADF
ID: USN-2311-1
Distribution: Ubuntu
Plattformen: Ubuntu 14.04 LTS
Datum: Di, 12. August 2014, 10:34
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4615
Applikationen: pyCADF

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============5751385001352358335==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="hSFjxPqQtMjrWcoOgRsaBGjEITpa0M96o"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--hSFjxPqQtMjrWcoOgRsaBGjEITpa0M96o
Content-Type: text/plain; charset=utf-
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-2311-1
August 11, 2014

python-pycadf vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS

Summary:

pyCADF could be made to expose sensitive information.

Software Description:
- python-pycadf: implementation of DMTF Cloud Audit (CADF) data model

Details:

Zhi Kun Liu discovered that pyCADF incorrectly filtered certain tokens.
An attacker could possibly use this issue to obtain authentication tokens
used in REST requests.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
python-pycadf 0.4.1-0ubuntu1.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2311-1
CVE-2014-4615

Package Information:
https://launchpad.net/ubuntu/+source/python-pycadf/0.4.1-0ubuntu1.1



--hSFjxPqQtMjrWcoOgRsaBGjEITpa0M96o
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJT6Py/AAoJEGVp2FWnRL6TwV0P/1aU9TuSFlMedyTPooXAhLcl
v2rvKtoHhsD6x3nTQWqSo8swuZN5xaUS15N2CWHe03NgShf/Fh0GzvAVGWy2yTpe
kfTT1B3kerEd0Xemks19n7X+bmOEV7jY/CChFOLQVrri3xS+Z+12M88wTzu6HE5k
4YeEi7afIJBtFShuMr8OTtjw89K9IWUNQtvfFyQH1R4eL4hHZ45nJxjBkO6KQEcg
PRvI4CzLlj4bFPzlBNu8H0ASS3tZmhNosc7g65zznTjX2ZwAZsAzb7ihP6CSbxxn
3AmzjFJ+gXIV8xecbuow91c+snWkQ6zjJfgEWL8yinE9EROBZJkfMuC2F5Cp0zud
ryOdg5zPriHSEDfimBGTBttDVdK6JbQ3PwbJJVxggEDAy6KTQiLLod964hM45dA3
vW0R0YPtz9jJqFGAKCh4xrzWXL67AG2WezeWiWIJlvpJFjeq1Qq6nDaZ5cbnqeLj
hMpsTFFuiKsxtpK6I492c4w+Q6iD+ihMFtdt1YEXgu4KamTQVXyBFPV7Bm4ydrd+
H3gzDePxYZymbaD5+6rdXvYtAS5QSBF2oleyUzj4dO46b2ICMNxK682MhsEiFnpr
dDNqpvQXU0H5IWUMHsvuyaUB486LsQS0/1BlT32jY2xwqDcoeUYe9FuyMsgk7WW2
osojm5DSx7fcWXY9PhFq
=3S03
-----END PGP SIGNATURE-----

--hSFjxPqQtMjrWcoOgRsaBGjEITpa0M96o--


--===============5751385001352358335==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============5751385001352358335==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung