Login
Newsletter
Werbung

Sicherheit: Zwei Probleme in OpenStack
Aktuelle Meldungen Distributionen
Name: Zwei Probleme in OpenStack
ID: USN-2704-1
Distribution: Ubuntu
Plattformen: Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 15.04
Datum: Do, 6. August 2015, 07:48
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1856
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7960
Applikationen: OpenStack

Originalnachricht


--===============4435502587069513851==
Content-Type: multipart/signed; micalg=pgp-sha1;
protocol="application/pgp-signature";
boundary="SLDf9lqlvOQaIe6s"
Content-Disposition: inline


--SLDf9lqlvOQaIe6s
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-2704-1
August 06, 2015

swift vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in Swift.

Software Description:
- swift: OpenStack distributed virtual object store

Details:

Rajaneesh Singh discovered Swift does not properly enforce metadata
limits. An attacker could abuse this issue to store more metadata than
allowed by policy. (CVE-2014-7960)

Clay Gerrard discovered Swift allowed users to delete the latest version
of object regardless of object permissions when allow_version is
configured. An attacker could use this issue to delete objects.
(CVE-2015-1856)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.04:
swift 2.2.2-0ubuntu1.3

Ubuntu 14.04 LTS:
swift 1.13.1-0ubuntu1.2

Ubuntu 12.04 LTS:
swift 1.4.8-0ubuntu2.5

After a standard system update you need to restart swift to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2704-1
CVE-2014-7960, CVE-2015-1856

Package Information:
https://launchpad.net/ubuntu/+source/swift/2.2.2-0ubuntu1.3
https://launchpad.net/ubuntu/+source/swift/1.13.1-0ubuntu1.2
https://launchpad.net/ubuntu/+source/swift/1.4.8-0ubuntu2.5


--SLDf9lqlvOQaIe6s
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEcBAEBAgAGBQJVwtNwAAoJEPMhclmdjS6X4QoH/1pggMsFS90EUK+3hkxEpfjc
ig88USQs2LAWTXcCWE7TxyB0K3HGwJpj9KeRcWnDaCDZ3aeXTcZ6zDgAJVT/pAxv
3sd9wP+2jQsY6CdgIOjWuaaDbPIgwaeXfNOkAmvEJNZw1FBc2737lgs0dJ50+GVH
i5xZA3yvpVCRP0Deu+zZJ8PW8h3JYWMvIsBFQIBdZu74SL/0on93TsXHad5Q0Cy4
r+zKAkhDIiJgcLnXqbxguHyWbf/ILm/00y5mrB8l48uPPP/TEY7CBX2f+uEyz5FA
o3Yagn4rFYZP1v4qUxNgXn2jH9+o8q/Lcdky5j5/jJCUh79z2jCU3Ul6bp4pcoY=
=l4Ig
-----END PGP SIGNATURE-----

--SLDf9lqlvOQaIe6s--


--===============4435502587069513851==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============4435502587069513851==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung