Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Ubuntu 12.10 USN-1772-1 Moderate: Keystone Network Access Threat

ubuntu
Calendar Grey March 20, 2013
Scroller Ubuntu
Critical flaw in Ubuntu's Keystone permits unauthorized network access. Apply updates promptly to resolve this vulnerability and strengthen security protocols.
Under certain configurations, Keystone would allow unintended access over the network.

Summary

Under certain configurations, Keystone would allow unintended access over

the network.

Software Description:

- keystone: OpenStack identity service

Details:

Guang Yee discovered that Keystone would not always perform all

verification checks when configured to use PKI. If the keystone server was

configured to use PKI and services or users requested online verification,

an attacker could potentially exploit this to bypass revocation checks.

Keystone uses UUID tokens by default in Ubuntu.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
  python-keystone                 2012.2.1-0ubuntu1.3

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1772-1

CVE-2013-1865

Severity
important
Lowest
Low
Medium
High
Critical

=========================================================================Ubuntu Security Notice USN-1772-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.