==========================================================================
Ubuntu Security Notice USN-2311-1
August 11, 2014
python-pycadf vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 14.04 LTS
Summary:
pyCADF could be made to expose sensitive information.
Software Description:
– python-pycadf: implementation of DMTF Cloud Audit (CADF) data model
Details:
Zhi Kun Liu discovered that pyCADF incorrectly filtered certain tokens.
An attacker could possibly use this issue to obtain authentication tokens
used in REST requests.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
python-pycadf 0.4.1-0ubuntu1.1
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2311-1
CVE-2014-4615
Package Information:
https://launchpad.net/ubuntu/+source/python-pycadf/0.4.1-0ubuntu1.1
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1
iQIcBAEBCgAGBQJT6Py/AAoJEGVp2FWnRL6TwV0P/1aU9TuSFlMedyTPooXAhLcl
v2rvKtoHhsD6x3nTQWqSo8swuZN5xaUS15N2CWHe03NgShf/Fh0GzvAVGWy2yTpe
kfTT1B3kerEd0Xemks19n7X+bmOEV7jY/CChFOLQVrri3xS+Z+12M88wTzu6HE5k
4YeEi7afIJBtFShuMr8OTtjw89K9IWUNQtvfFyQH1R4eL4hHZ45nJxjBkO6KQEcg
PRvI4CzLlj4bFPzlBNu8H0ASS3tZmhNosc7g65zznTjX2ZwAZsAzb7ihP6CSbxxn
3AmzjFJ+gXIV8xecbuow91c+snWkQ6zjJfgEWL8yinE9EROBZJkfMuC2F5Cp0zud
ryOdg5zPriHSEDfimBGTBttDVdK6JbQ3PwbJJVxggEDAy6KTQiLLod964hM45dA3
vW0R0YPtz9jJqFGAKCh4xrzWXL67AG2WezeWiWIJlvpJFjeq1Qq6nDaZ5cbnqeLj
hMpsTFFuiKsxtpK6I492c4w+Q6iD+ihMFtdt1YEXgu4KamTQVXyBFPV7Bm4ydrd+
H3gzDePxYZymbaD5+6rdXvYtAS5QSBF2oleyUzj4dO46b2ICMNxK682MhsEiFnpr
dDNqpvQXU0H5IWUMHsvuyaUB486LsQS0/1BlT32jY2xwqDcoeUYe9FuyMsgk7WW2
osojm5DSx7fcWXY9PhFq
=3S03
—–END PGP SIGNATURE—–
—