Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 12.04 LTS USN-1552-1 Critical: Keystone Admin Access Flaws

ubuntu
Calendar Grey September 3, 2012
Scroller Ubuntu
Recent vulnerabilities identified in OpenStack Keystone for Ubuntu 12.04 LTS highlight the need for prompt updates to safeguard against potential breaches.
Two security issues were fixed in OpenStack Keystone.

Summary

Two security issues were fixed in OpenStack Keystone.

Software Description:

- keystone: OpenStack identity service

Details:

Dolph Mathews discovered that OpenStack Keystone did not properly

restrict to administrative users the ability to update users'

tenants. A remote attacker that can reach the administrative API can

use this to add any user to any tenant. (CVE-2012-3542)

Derek Higgins discovered that OpenStack Keystone did not properly

implement token expiration. A remote attacker could use this to

continue to access an account that has been disabled or has a changed

password. (CVE-2012-3426)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  keystone                        2012.1+stable~20120824-a16a0ab9-0ubuntu2.1
  python-keystone                 2012.1+stable~20120824-a16a0ab9-0ubuntu2.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1552-1

CVE-2012-3426, CVE-2012-3542

Severity
critical
Lowest
Low
Medium
High
Critical

September 03, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.