LWN.net Logo

Fedora alert FEDORA-2013-14302 (python-keystoneclient)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 19 Update: python-keystoneclient-0.2.3-7.fc19
Date:  Thu, 15 Aug 2013 02:35:03 +0000
Message-ID:  <20130815023503.5FF30211EF@bastion01.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2013-14302 2013-08-06 22:03:19 -------------------------------------------------------------------------------- Name : python-keystoneclient Product : Fedora 19 Version : 0.2.3 Release : 7.fc19 URL : http://pypi.python.org/pypi/python-keystoneclient Summary : Client library for OpenStack Identity API Description : Client library and command line utility for interacting with Openstack Identity API. -------------------------------------------------------------------------------- Update Information: Selective backports from stable/grizzly: * Ec2Signer: Initial support for v4 signature verification. * Allow signature verification for older boto versions. * Default signing_dir to secure temp dir. * Fix memcache encryption middleware. (CVE-2013-2166, CVE-2013-2167) * Check token expiry. (CVE-2013-2104) * Allow secure user password update. (CVE-2013-2013) -------------------------------------------------------------------------------- ChangeLog: * Mon Aug 5 2013 Jakub Ruzicka <jruzicka@redhat.com> 0.2.3-7 - Ec2Signer: Allow signature verification for older boto versions. (#984752) * Mon Jul 29 2013 Jakub Ruzicka <jruzicka@redhat.com> 0.2.3-6 - Allow secure user password update. (CVE-2013-2013) * Thu Jul 25 2013 Jakub Ruzicka <jruzicka@redhat.com> 0.2.3-5 - Ec2Signer: Initial support for v4 signature verification. - Default signing_dir to secure temp dir. - Fix memcache encryption middleware. (CVE-2013-2166, CVE-2013-2167) * Tue May 28 2013 Jakub Ruzicka <jruzicka@redhat.com> 0.2.3-4 - Check token expiry. (CVE-2013-2104) -------------------------------------------------------------------------------- References: [ 1 ] Bug #974271 - CVE-2013-2166 CVE-2013-2167 python-keystoneclient: middleware memcache encryption and signing bypass https://bugzilla.redhat.com/show_bug.cgi?id=974271 [ 2 ] Bug #965852 - CVE-2013-2104 OpenStack Keystone: Missing expiration check in Keystone PKI token validation https://bugzilla.redhat.com/show_bug.cgi?id=965852 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update python-keystoneclient' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds