Home
Reading
Searching
Subscribe
Sponsors
Statistics
Posting
Contact
Spam
Lists
Links
About
Hosting
Filtering
Features Download
Marketing
Archives
FAQ
Blog
 
Gmane
From: <updates <at> fedoraproject.org>
Subject: [SECURITY] Fedora 19 Update: python-keystoneclient-0.2.3-7.fc19
Newsgroups: gmane.linux.redhat.fedora.package.announce
Date: Thursday 15th August 2013 02:35:03 UTC (over 3 years ago)
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2013-14302
2013-08-06 22:03:19
--------------------------------------------------------------------------------

Name        : python-keystoneclient
Product     : Fedora 19
Version     : 0.2.3
Release     : 7.fc19
URL         : http://pypi.python.org/pypi/python-keystoneclient
Summary     : Client library for OpenStack Identity API
Description :
Client library and command line utility for interacting with Openstack
Identity API.

--------------------------------------------------------------------------------
Update Information:

Selective backports from stable/grizzly:
 * Ec2Signer: Initial support for v4 signature verification.
 * Allow signature verification for older boto versions.
 * Default signing_dir to secure temp dir.
 * Fix memcache encryption middleware. (CVE-2013-2166, CVE-2013-2167)
 * Check token expiry. (CVE-2013-2104)
 * Allow secure user password update. (CVE-2013-2013)

--------------------------------------------------------------------------------
ChangeLog:

* Mon Aug  5 2013 Jakub Ruzicka <[email protected]> 0.2.3-7
- Ec2Signer: Allow signature verification for older boto versions.
(#984752)
* Mon Jul 29 2013 Jakub Ruzicka <[email protected]> 0.2.3-6
- Allow secure user password update. (CVE-2013-2013)
* Thu Jul 25 2013 Jakub Ruzicka <[email protected]> 0.2.3-5
- Ec2Signer: Initial support for v4 signature verification.
- Default signing_dir to secure temp dir.
- Fix memcache encryption middleware. (CVE-2013-2166, CVE-2013-2167)
* Tue May 28 2013 Jakub Ruzicka <[email protected]> 0.2.3-4
- Check token expiry. (CVE-2013-2104)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #974271 - CVE-2013-2166 CVE-2013-2167 python-keystoneclient:
middleware memcache encryption and signing bypass
        https://bugzilla.redhat.com/show_bug.cgi?id=974271
  [ 2 ] Bug #965852 - CVE-2013-2104 OpenStack Keystone: Missing expiration
check in Keystone PKI token validation
        https://bugzilla.redhat.com/show_bug.cgi?id=965852
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update python-keystoneclient' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on
the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
[email protected]
https://admin.fedoraproject.org/mailman/listinfo/package-announce
 
CD: 3ms