==========================================================================
Ubuntu Security Notice USN-2207-1
May 06, 2014
swift vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 13.10
– Ubuntu 12.10
– Ubuntu 12.04 LTS
Summary:
OpenStack Swift would allow unintended access to files over the network.
Software Description:
– swift: OpenStack distributed virtual object store
Details:
Samuel Merritt discovered a timing attack vulnerability in OpenStack Swift.
If Swift was configured to use the TempURL middleware, an attacker could
exploit this to guess valid secret URLs and obtain unintended access to
objects publicly shared with specific recipients.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.10:
python-swift 1.10.0-0ubuntu1.1
Ubuntu 12.10:
python-swift 1.7.4-0ubuntu2.4
Ubuntu 12.04 LTS:
python-swift 1.4.8-0ubuntu2.4
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2207-1
CVE-2014-0006
Package Information:
https://launchpad.net/ubuntu/+source/swift/1.10.0-0ubuntu1.1
https://launchpad.net/ubuntu/+source/swift/1.7.4-0ubuntu2.4
https://launchpad.net/ubuntu/+source/swift/1.4.8-0ubuntu2.4
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1
Comment: Using GnuPG with Thunderbird – http://www.enigmail.net/
iQIcBAEBCgAGBQJTaUFUAAoJEFHb3FjMVZVzxNMQAJH+ETB25vqfEPfm/y4bvFoK
ROVkmJAG+3hLvEVG8FIRhSMz1h5gXIICu5crD3j0Yt98ryeOMncfMX5vlfTmzW2I
A1oOQrshyeC+bPhcJqu1m/+rDi7BOq1tgWV5Se4DeRsxwuPR9Cubsvm7uLdo0EhY
0S5RAMp8v/ip5nN9jutyCSyuO6qEW836oG/T0G4EqaG4mTAB5G5bty/WWGyEYUUU
p40tbuQ+iL3SXXXZw0mFWVOIvFo1T8OsfKcrj2nXXJscFQofWxaINW0LUAgDzFG+
PYfWcvKxe1kOZLMc3a1s2jvKCEO0TUa8uvvM7nO/FTr06opTra28O3d1+wZHvsa6
dR09bAi3r6zTFGfzDCKa0VkyuHgWf5rwg6OPa/pLj/JLmk4FuSqDlECk/5q/Roeg
jEqq+3XlVGnhHw2ihofXP/FgxRlThGvElfdW9SzQxHMrTlkSXmIY9gEHCVmCT+hm
a9UFTL46qQiGlpGIM0k4oRLn7LKTklpgzs3VLMctH2U/K8K9CsS45XsLDAbMj9H7
QzHoWYb4V8ZEZBEhJTEG6YK19Ei5g4k/bTsB5dOV09lv5zSfKCBZyFy0lnDKvRPK
HjGWatbLFbR1C2UW8A6PWZtJV/JxR7QjMPqhonpNCTLR7N6KWdcuQpJfFwrajD6e
20nVA9AdSN2BbbHrqXDS
=52fe
—–END PGP SIGNATURE—–
—