Ubuntu 1033-1: Eucalyptus vulnerability

    Date16 Dec 2010
    CategoryUbuntu
    37
    Posted ByLinuxSecurity Advisories
    It was discovered that Eucalyptus did not verify password resets fromthe Admin UI correctly. An unauthenticated remote attacker could issuepassword reset requests to gain admin privileges in the Eucalyptusenvironment. [More...]
    ===========================================================
    Ubuntu Security Notice USN-1033-1         December 16, 2010
    eucalyptus vulnerability
    CVE-2010-3905
    ===========================================================
    
    A security issue affects the following Ubuntu releases:
    
    Ubuntu 10.10
    
    This advisory also applies to the corresponding versions of
    Kubuntu, Edubuntu, and Xubuntu.
    
    The problem can be corrected by upgrading your system to the
    following package versions:
    
    Ubuntu 10.10:
      eucalyptus-java-common          2.0+bzr1241-0ubuntu4.1
    
    In general, a standard system update will make all the necessary changes.
    
    Details follow:
    
    It was discovered that Eucalyptus did not verify password resets from
    the Admin UI correctly. An unauthenticated remote attacker could issue
    password reset requests to gain admin privileges in the Eucalyptus
    environment.
    
    
    Updated packages for Ubuntu 10.10:
    
      Source archives:
    
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus_2.0+bzr1241-0ubuntu4.1.debian.tar.gz
          Size/MD5:  1089703 f069164d6b2ca21b88576a3ca0b9c2c4
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus_2.0+bzr1241-0ubuntu4.1.dsc
          Size/MD5:     3130 cc4ffed69d917b9b79a1e55ce4e4cce5
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus_2.0+bzr1241.orig.tar.gz
          Size/MD5:  1125937 53aa41e05e82eb21b9c22986b908bb90
    
      amd64 architecture (Athlon64, Opteron, EM64T Xeon):
    
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus-cc_2.0+bzr1241-0ubuntu4.1_amd64.deb
          Size/MD5:   521416 38de80370f3ee94f76830c29595d2fde
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus-cloud_2.0+bzr1241-0ubuntu4.1_amd64.deb
          Size/MD5:   297032 859b7a1d592ef6bfb0d0e336ac4df096
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus-common_2.0+bzr1241-0ubuntu4.1_amd64.deb
          Size/MD5:   442732 ecf1716a8c5550632769e93faf6c653d
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus-gl_2.0+bzr1241-0ubuntu4.1_amd64.deb
          Size/MD5:    58358 924adeb96eae67118ea48ce66ccdd1de
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus-java-common_2.0+bzr1241-0ubuntu4.1_amd64.deb
          Size/MD5:  5823190 9e2d42104ae6d4e99b73b9af3767b3ed
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus-nc_2.0+bzr1241-0ubuntu4.1_amd64.deb
          Size/MD5:   295222 b2a2b8e919da3190fd7fc6b62eee3fd0
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus-sc_2.0+bzr1241-0ubuntu4.1_amd64.deb
          Size/MD5:    83592 24f5a556f6efe3370c65fdbc9fcfad9b
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus-udeb_2.0+bzr1241-0ubuntu4.1_amd64.udeb
          Size/MD5:    11386 ad7098126c99e9cf6b01be308fd15558
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus-walrus_2.0+bzr1241-0ubuntu4.1_amd64.deb
          Size/MD5:    95918 554c4d2a8a54c96ffb2f6df06150a771
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/uec-component-listener_2.0+bzr1241-0ubuntu4.1_amd64.deb
          Size/MD5:     9840 12f99f596ecb7663227fa252d6f98ed8
    
      i386 architecture (x86 compatible Intel/AMD):
    
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus-cc_2.0+bzr1241-0ubuntu4.1_i386.deb
          Size/MD5:   456010 d3d65bdc406ffc849229db07fc932ed8
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus-cloud_2.0+bzr1241-0ubuntu4.1_i386.deb
          Size/MD5:   296976 c897fe371e8cf30ce2ebfaa370a4ee2f
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus-common_2.0+bzr1241-0ubuntu4.1_i386.deb
          Size/MD5:   380950 9ffa8290b6a8c0170a8469cdbfb9e4aa
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus-gl_2.0+bzr1241-0ubuntu4.1_i386.deb
          Size/MD5:    51464 95f8361795cd1a1f7371ed32b6c85bb9
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus-java-common_2.0+bzr1241-0ubuntu4.1_i386.deb
          Size/MD5:  5824096 3dac8ecf2fd4e1d1a3c4334678f8e827
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus-nc_2.0+bzr1241-0ubuntu4.1_i386.deb
          Size/MD5:   257456 fce08ca26921c9fdac1cb0191b2c03b8
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus-sc_2.0+bzr1241-0ubuntu4.1_i386.deb
          Size/MD5:    83366 7cdad21c04f47a85fbba9549b4c5af91
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus-udeb_2.0+bzr1241-0ubuntu4.1_i386.udeb
          Size/MD5:    10788 717ac6e2fa4cb9cff22a2e9438cfe304
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/eucalyptus-walrus_2.0+bzr1241-0ubuntu4.1_i386.deb
          Size/MD5:    95682 7af42d18b09a7d9793d916588919b0ce
        http://security.ubuntu.com/ubuntu/pool/main/e/eucalyptus/uec-component-listener_2.0+bzr1241-0ubuntu4.1_i386.deb
          Size/MD5:     9068 74a75f5e3609cf0d99b749e464c0fcd3
    
      powerpc architecture (Apple Macintosh G3/G4/G5):
    
        http://ports.ubuntu.com/pool/main/e/eucalyptus/eucalyptus-cc_2.0+bzr1241-0ubuntu4.1_powerpc.deb
          Size/MD5:   484390 6f8a2db6d5ccae20a546ea6dd9ab8292
        http://ports.ubuntu.com/pool/main/e/eucalyptus/eucalyptus-cloud_2.0+bzr1241-0ubuntu4.1_powerpc.deb
          Size/MD5:   297160 d49246ad399a4e09cde53c9df202106b
        http://ports.ubuntu.com/pool/main/e/eucalyptus/eucalyptus-common_2.0+bzr1241-0ubuntu4.1_powerpc.deb
          Size/MD5:   372256 30fc79eced7a8b97397da0cb0e813096
        http://ports.ubuntu.com/pool/main/e/eucalyptus/eucalyptus-gl_2.0+bzr1241-0ubuntu4.1_powerpc.deb
          Size/MD5:    54520 7410a9f4ceaf409f578b0f70ff0b5f9e
        http://ports.ubuntu.com/pool/main/e/eucalyptus/eucalyptus-java-common_2.0+bzr1241-0ubuntu4.1_powerpc.deb
          Size/MD5:  5823590 ae02398e3cfc0f9d2d41a92e5cb08ed2
        http://ports.ubuntu.com/pool/main/e/eucalyptus/eucalyptus-nc_2.0+bzr1241-0ubuntu4.1_powerpc.deb
          Size/MD5:   273576 35b76654f50b4b4fb2244c42b8634dac
        http://ports.ubuntu.com/pool/main/e/eucalyptus/eucalyptus-sc_2.0+bzr1241-0ubuntu4.1_powerpc.deb
          Size/MD5:    83624 97c51d97f7b22e016dde4cfb76f50d77
        http://ports.ubuntu.com/pool/main/e/eucalyptus/eucalyptus-udeb_2.0+bzr1241-0ubuntu4.1_powerpc.udeb
          Size/MD5:    11236 529ab9ec3dabeedff99676ab3d291c97
        http://ports.ubuntu.com/pool/main/e/eucalyptus/eucalyptus-walrus_2.0+bzr1241-0ubuntu4.1_powerpc.deb
          Size/MD5:    95974 9a6fe4ce4c41c3045935bbaaf36bf1c8
        http://ports.ubuntu.com/pool/main/e/eucalyptus/uec-component-listener_2.0+bzr1241-0ubuntu4.1_powerpc.deb
          Size/MD5:     9532 54837904b0034e3bc7179033a22df851
    
    You are not authorised to post comments.

    Comments powered by CComment

    LinuxSecurity Poll

    What do you think of the articles on LinuxSecurity?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 3 answer(s).
    /main-polls/24-what-do-you-think-of-the-quality-of-the-articles-on-linuxsecurity?task=poll.vote&format=json
    24
    radio
    [{"id":"87","title":"Excellent, don't change a thing!","votes":"23","type":"x","order":"1","pct":53.49,"resources":[]},{"id":"88","title":"Should be more technical","votes":"5","type":"x","order":"2","pct":11.63,"resources":[]},{"id":"89","title":"Should include more HOWTOs","votes":"15","type":"x","order":"3","pct":34.88,"resources":[]}]["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"]["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"]350
    bottom200

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.