You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa OpenStack Swift

Sigurnosni nedostaci programskog paketa OpenStack Swift

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-3451-1
October 11, 2017

swift vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in OpenStack Swift.

Software Description:
– swift: OpenStack distributed virtual object store

Details:

It was discovered that OpenStack Swift incorrectly handled tempurls. A
remote authenticated user in possession of a tempurl key authorized for PUT
could retrieve other objects in the same Swift account. (CVE-2015-5223)

Romain Le Disez and Örjan Persson discovered that OpenStack Swift
incorrectly closed client connections. A remote attacker could possibly use
this issue to consume resources, resulting in a denial of service.
(CVE-2016-0737, CVE-2016-0738)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
python-swift 1.13.1-0ubuntu1.5
swift 1.13.1-0ubuntu1.5

In general, a standard system update will make all the necessary changes.

References:
https://www.ubuntu.com/usn/usn-3451-1
CVE-2015-5223, CVE-2016-0737, CVE-2016-0738

Package Information:
https://launchpad.net/ubuntu/+source/swift/1.13.1-0ubuntu1.5

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQIcBAEBCgAGBQJZ3hulAAoJEGVp2FWnRL6TjKUP/3nEXlhfMNf+QkNxYTCMu8tx
+O9RlIINsGjibOE/WF5cclMrs0J6m6gTBeO8+89jzXOQw1Jm1+N1gMAteWRN8Eti
up2Q3KzYhidgorl7MDfjjOeAlkXSA5K0tIg3pyR8j2g4HHhCKkn/2ty1V3HzPGxM
73pKqI/0sjzBQLLrIJrBG9l1cbZGiWjn7Vs1WZYaVf30Pbuhfzo3R9+vu4wGFvpu
HlFMcaJaQAlgGK7aWU/StIOIjJ+s9LuwWB4deAc8bfMoTk1eqRDWgPWzWVV1tEMl
ZqtfdZp3KzIqe/Ejy1vpxP19VBzZvixHDce2ZY+yBsjOpKvgAPVfkeoT6jUswDyd
rEwSGTJpRrq3wMJqDQjR23HlF4DWuR3eyGCyAMATf4NdEsfrlobcSUijDcZ6eZGp
62Kih9S5A225DxHUygxIot7OhkTg6SHPqt+ArbWY88h4qAeB3WfvoP9SSula5q6U
jn/Cc+1WJbR61pQJGs9upB2Cjh2n4jFIASOccG61aduZalNkpDVjCwkTcGerO7Ct
GN6E775zAUiqJnhV3OgyoUaLwUAe1a2owUHR4mFBQiKlvmkuU+xtBLD7rsvX57eM
UxIRb/QE5haABWo6n2WYih5TBI5PlrU08D1Lr9SnFITZpYdqrige0OQCzs0bkOWu
UbEiL7+VLOI2u1xGSAyt
=HtrY
—–END PGP SIGNATURE—–

AutorDanijel Kozinovic
Cert idNCERT-REF-2017-10-0083-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa openvswitch

Otkriveni su sigurnosni nedostaci u programskom paketu openvswitch za Ubuntu 16.04 LTS i 17.04. Otkriveni nedostaci potencijalnim napadačima omogućuju izvođenje...

Close