You are here
Home > Preporuke > Sigurnosni propust programskog paketa pyCADF

Sigurnosni propust programskog paketa pyCADF

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-2311-1
August 11, 2014

python-pycadf vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 14.04 LTS

Summary:

pyCADF could be made to expose sensitive information.

Software Description:
– python-pycadf: implementation of DMTF Cloud Audit (CADF) data model

Details:

Zhi Kun Liu discovered that pyCADF incorrectly filtered certain tokens.
An attacker could possibly use this issue to obtain authentication tokens
used in REST requests.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
python-pycadf 0.4.1-0ubuntu1.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2311-1
CVE-2014-4615

Package Information:
https://launchpad.net/ubuntu/+source/python-pycadf/0.4.1-0ubuntu1.1

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1

iQIcBAEBCgAGBQJT6Py/AAoJEGVp2FWnRL6TwV0P/1aU9TuSFlMedyTPooXAhLcl
v2rvKtoHhsD6x3nTQWqSo8swuZN5xaUS15N2CWHe03NgShf/Fh0GzvAVGWy2yTpe
kfTT1B3kerEd0Xemks19n7X+bmOEV7jY/CChFOLQVrri3xS+Z+12M88wTzu6HE5k
4YeEi7afIJBtFShuMr8OTtjw89K9IWUNQtvfFyQH1R4eL4hHZ45nJxjBkO6KQEcg
PRvI4CzLlj4bFPzlBNu8H0ASS3tZmhNosc7g65zznTjX2ZwAZsAzb7ihP6CSbxxn
3AmzjFJ+gXIV8xecbuow91c+snWkQ6zjJfgEWL8yinE9EROBZJkfMuC2F5Cp0zud
ryOdg5zPriHSEDfimBGTBttDVdK6JbQ3PwbJJVxggEDAy6KTQiLLod964hM45dA3
vW0R0YPtz9jJqFGAKCh4xrzWXL67AG2WezeWiWIJlvpJFjeq1Qq6nDaZ5cbnqeLj
hMpsTFFuiKsxtpK6I492c4w+Q6iD+ihMFtdt1YEXgu4KamTQVXyBFPV7Bm4ydrd+
H3gzDePxYZymbaD5+6rdXvYtAS5QSBF2oleyUzj4dO46b2ICMNxK682MhsEiFnpr
dDNqpvQXU0H5IWUMHsvuyaUB486LsQS0/1BlT32jY2xwqDcoeUYe9FuyMsgk7WW2
osojm5DSx7fcWXY9PhFq
=3S03
—–END PGP SIGNATURE—–

AutorMarko Stanec
Cert idNCERT-REF-2014-08-0044-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa libav

Otkriven je sigurnosni nedostatak u programskom paketu libav za operacijski sustav Ubuntu. Otkriveni nedostatak potencijalnim napadačima omogućuje izvršavanje proizvoljnog programskog...

Close