You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa OpenStack swift

Sigurnosni nedostatak programskog paketa OpenStack swift

==========================================================================
Ubuntu Security Notice USN-2207-1
May 06, 2014

swift vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 13.10
– Ubuntu 12.10
– Ubuntu 12.04 LTS

Summary:

OpenStack Swift would allow unintended access to files over the network.

Software Description:
– swift: OpenStack distributed virtual object store

Details:

Samuel Merritt discovered a timing attack vulnerability in OpenStack Swift.
If Swift was configured to use the TempURL middleware, an attacker could
exploit this to guess valid secret URLs and obtain unintended access to
objects publicly shared with specific recipients.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
python-swift 1.10.0-0ubuntu1.1

Ubuntu 12.10:
python-swift 1.7.4-0ubuntu2.4

Ubuntu 12.04 LTS:
python-swift 1.4.8-0ubuntu2.4

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2207-1
CVE-2014-0006

Package Information:
https://launchpad.net/ubuntu/+source/swift/1.10.0-0ubuntu1.1
https://launchpad.net/ubuntu/+source/swift/1.7.4-0ubuntu2.4
https://launchpad.net/ubuntu/+source/swift/1.4.8-0ubuntu2.4

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1
Comment: Using GnuPG with Thunderbird – http://www.enigmail.net/

iQIcBAEBCgAGBQJTaUFUAAoJEFHb3FjMVZVzxNMQAJH+ETB25vqfEPfm/y4bvFoK
ROVkmJAG+3hLvEVG8FIRhSMz1h5gXIICu5crD3j0Yt98ryeOMncfMX5vlfTmzW2I
A1oOQrshyeC+bPhcJqu1m/+rDi7BOq1tgWV5Se4DeRsxwuPR9Cubsvm7uLdo0EhY
0S5RAMp8v/ip5nN9jutyCSyuO6qEW836oG/T0G4EqaG4mTAB5G5bty/WWGyEYUUU
p40tbuQ+iL3SXXXZw0mFWVOIvFo1T8OsfKcrj2nXXJscFQofWxaINW0LUAgDzFG+
PYfWcvKxe1kOZLMc3a1s2jvKCEO0TUa8uvvM7nO/FTr06opTra28O3d1+wZHvsa6
dR09bAi3r6zTFGfzDCKa0VkyuHgWf5rwg6OPa/pLj/JLmk4FuSqDlECk/5q/Roeg
jEqq+3XlVGnhHw2ihofXP/FgxRlThGvElfdW9SzQxHMrTlkSXmIY9gEHCVmCT+hm
a9UFTL46qQiGlpGIM0k4oRLn7LKTklpgzs3VLMctH2U/K8K9CsS45XsLDAbMj9H7
QzHoWYb4V8ZEZBEhJTEG6YK19Ei5g4k/bTsB5dOV09lv5zSfKCBZyFy0lnDKvRPK
HjGWatbLFbR1C2UW8A6PWZtJV/JxR7QjMPqhonpNCTLR7N6KWdcuQpJfFwrajD6e
20nVA9AdSN2BbbHrqXDS
=52fe
—–END PGP SIGNATURE—–

Top
More in Preporuke
Sigurnosni nedostatak programskog paketa OpenStack horizon

Otkriven je sigurnosni nedostatak u programskom paketu OpenStack horizon za Ubuntu 13.10. Otkriveni nedostatak potencijalnim napadačima omogućuje izvođenje XSS napada...

Close