Alerts This Week
Warning Icon 1 1,229
Alerts This Week
Warning Icon 1 1,229

Ubuntu 13.10: USN-2034-1 Moderate: Keystone LDAP Privilege Escalation

ubuntu
Calendar Grey November 25, 2013
Dist Ubuntu Esm H88
A vital security concern on Fedora might facilitate unauthorized elevation of user privileges. Ensure you upgrade your system to protect against this vulnerability.
Keystone would improperly remove roles when it was configured to use the LDAP backend.

Summary

Keystone would improperly remove roles when it was configured to use the

LDAP backend.

Software Description:

- keystone: OpenStack identity service

Details:

Brant Knudson discovered a logic error in the LDAP backend in Keystone

where removing a role on a tenant for a user who does not have that role

would instead add the role to the user. An authenticated user could use

this to gain privileges. Ubuntu is not configured to use the LDAP Keystone

backend by default.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  python-keystone                 1:2013.2-0ubuntu1.1

Ubuntu 13.04:
  python-keystone                 1:2013.1.4-0ubuntu1.1

Ubuntu 12.10:
  python-keystone                 2012.2.4-0ubuntu3.3

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2034-1

CVE-2013-4477

=========================================================================Ubuntu Security Notice USN-2034-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here