Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0, 6.0, and 7.0. [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-swift security update Advisory ID: RHSA-2015:1895-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2015:1895.html Issue date: 2015-10-15 CVE Names: CVE-2015-5223 ==================================================================== 1. Summary: Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0, 6.0, and 7.0. Red Hat Product Security has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6 - noarch Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 7 - noarch Red Hat Enterprise Linux OpenStack Platform 6.0 for RHEL 7 - noarch Red Hat Enterprise Linux OpenStack Platform 7.0 for RHEL 7 - noarch 3. Description: OpenStack Object Storage (swift) provides object storage in virtual containers, which allows users to store and retrieve files (arbitrary data). The service's distributed architecture supports horizontal scaling; redundancy as failure-proofing is provided through software-based data replication. Because Object Storage supports asynchronous eventual consistency replication, it is well suited to deployment in multiple data centers. A flaw was found in the OpenStack Object storage service (swift) tempurls. An attacker in possession of a tempurl key with PUT permissions may be able to gain read access to other objects in the same project. (CVE-2015-5223) Red Hat would like tothank the OpenStack project for reporting this issue. Upstream acknowledges Richard Hawkins of Rackspace, and the OpenStack Swift core reviewers as the original reporters. All users of openstack-swift are advised to upgrade to these updated packages, which correct this issue. After installing this update, the OpenStack Object Storage services will be restarted automatically. 4. Solution: Before applying this update, ensure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1255622 - CVE-2015-5223 openstack-swift: Information leak via Swift tempurls 6. Package List: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6: Source: openstack-swift-1.13.1-7.el6ost.src.rpm noarch: openstack-swift-1.13.1-7.el6ost.noarch.rpm openstack-swift-account-1.13.1-7.el6ost.noarch.rpm openstack-swift-container-1.13.1-7.el6ost.noarch.rpm openstack-swift-doc-1.13.1-7.el6ost.noarch.rpm openstack-swift-object-1.13.1-7.el6ost.noarch.rpm openstack-swift-proxy-1.13.1-7.el6ost.noarch.rpm Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 7: Source: openstack-swift-1.13.1-7.el7ost.src.rpm noarch: openstack-swift-1.13.1-7.el7ost.noarch.rpm openstack-swift-account-1.13.1-7.el7ost.noarch.rpm openstack-swift-container-1.13.1-7.el7ost.noarch.rpm openstack-swift-doc-1.13.1-7.el7ost.noarch.rpm openstack-swift-object-1.13.1-7.el7ost.noarch.rpm openstack-swift-proxy-1.13.1-7.el7ost.noarch.rpm Red Hat Enterprise Linux OpenStack Platform 6.0 for RHEL 7: Source: openstack-swift-2.2.0-5.el7ost.src.rpm noarch: openstack-swift-2.2.0-5.el7ost.noarch.rpm openstack-swift-account-2.2.0-5.el7ost.noarch.rpm openstack-swift-container-2.2.0-5.el7ost.noarch.rpm openstack-swift-doc-2.2.0-5.el7ost.noarch.rpm openstack-swift-object-2.2.0-5.el7ost.noarch.rpm openstack-swift-proxy-2.2.0-5.el7ost.noarch.rpm Red Hat Enterprise Linux OpenStack Platform 7.0 for RHEL7: Source: openstack-swift-2.3.0-2.el7ost.src.rpm noarch: openstack-swift-2.3.0-2.el7ost.noarch.rpm openstack-swift-account-2.3.0-2.el7ost.noarch.rpm openstack-swift-container-2.3.0-2.el7ost.noarch.rpm openstack-swift-doc-2.3.0-2.el7ost.noarch.rpm openstack-swift-object-2.3.0-2.el7ost.noarch.rpm openstack-swift-proxy-2.3.0-2.el7ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2015-5223 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2015 Red Hat, Inc. . OpenStack team released a significant security notice concerning swift packages to tackle potential risks in data retrieval.. openstack swift update, Red Hat advisory, security patches, object storage security. . LinuxSecurity.com Team
Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0. Red Hat Product Security has rated this update as having Moderate security [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-swift security update Advisory ID: RHSA-2015:1684-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2015:1684.html Issue date: 2015-08-25 CVE Names: CVE-2015-1856 ==================================================================== 1. Summary: Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0. Red Hat Product Security has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6 - noarch Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 7 - noarch 3. Description: OpenStack Object Storage (swift) provides object storage in virtual containers, which allows users to store and retrieve files (arbitrary data). The service's distributed architecture supports horizontal scaling; redundancy as failure-proofing is provided through software-based data replication. Because Object Storage supports asynchronous eventual consistency replication, it is well suited to multiple data-center deployment. A flaw was found in OpenStack Object Storage that could allow an authenticated user to delete the most recent version of a versioned object regardless of ownership. To exploit this flaw, an attacker must know the name of the object and have listing access to the x-versions-location container. (CVE-2015-1856) Red Hat would like to thankthe OpenStack project for reporting this issue. Upstream acknowledges Clay Gerrard of SwiftStack as the original reporter. All users of openstack-swift are advised to upgrade to these updated packages, which correct this issue. After installing this update, the OpenStack Object Storage services will be restarted automatically. 4. Solution: Before applying this update, ensure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1209994 - CVE-2015-1856 OpenStack Swift: unauthorized deletion of versioned Swift object 6. Package List: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6: Source: openstack-swift-1.13.1-6.el6ost.src.rpm noarch: openstack-swift-1.13.1-6.el6ost.noarch.rpm openstack-swift-account-1.13.1-6.el6ost.noarch.rpm openstack-swift-container-1.13.1-6.el6ost.noarch.rpm openstack-swift-doc-1.13.1-6.el6ost.noarch.rpm openstack-swift-object-1.13.1-6.el6ost.noarch.rpm openstack-swift-proxy-1.13.1-6.el6ost.noarch.rpm Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 7: Source: openstack-swift-1.13.1-5.el7ost.src.rpm noarch: openstack-swift-1.13.1-5.el7ost.noarch.rpm openstack-swift-account-1.13.1-5.el7ost.noarch.rpm openstack-swift-container-1.13.1-5.el7ost.noarch.rpm openstack-swift-doc-1.13.1-5.el7ost.noarch.rpm openstack-swift-object-1.13.1-5.el7ost.noarch.rpm openstack-swift-proxy-1.13.1-5.el7ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-1856 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. . Red Hat has released a security advisory regarding asignificant vulnerability in OpenStack Swift affecting object storage management, urging immediate reviews and updates.. Red Hat OpenStack, Object Storage Security, OpenStack Swift Update. . LinuxSecurity.com Team
Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 6.0. Red Hat Product Security has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-swift security update Advisory ID: RHSA-2015:1681-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2015:1681.html Issue date: 2015-08-24 CVE Names: CVE-2015-1856 ==================================================================== 1. Summary: Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 6.0. Red Hat Product Security has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux OpenStack Platform 6.0 for RHEL 7 - noarch 3. Description: OpenStack Object Storage (swift) provides object storage in virtual containers, which allows users to store and retrieve files (arbitrary data). The service's distributed architecture supports horizontal scaling; redundancy as failure-proofing is provided through software-based data replication. Because Object Storage supports asynchronous eventual consistency replication, it is well suited to multiple data-center deployment. A flaw was found in openstack-swift where an authenticated user may delete the most recent version of a versioned object regardless of ownership. To exploit this flaw an attacker most know the name of the object and have listing access to the x-versions-location container. (CVE-2015-1856) Red Hat wouldlike to thank the OpenStack project for reporting this issue. Upstream acknowledges Clay Gerrard of SwiftStack as the original reporter. All users of openstack-swift are advised to upgrade to these updated packages, which correct this issue. After installing this update, the OpenStack Object Storage services will be restarted automatically. 4. Solution: Before applying this update, ensure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1209994 - CVE-2015-1856 OpenStack Swift: unauthorized deletion of versioned Swift object 6. Package List: Red Hat Enterprise Linux OpenStack Platform 6.0 for RHEL 7: Source: openstack-swift-2.2.0-4.el7ost.src.rpm noarch: openstack-swift-2.2.0-4.el7ost.noarch.rpm openstack-swift-account-2.2.0-4.el7ost.noarch.rpm openstack-swift-container-2.2.0-4.el7ost.noarch.rpm openstack-swift-doc-2.2.0-4.el7ost.noarch.rpm openstack-swift-object-2.2.0-4.el7ost.noarch.rpm openstack-swift-proxy-2.2.0-4.el7ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-1856 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFV251KXlSAg2UNWIIRAtWlAKDA6zAkOV4UPJUKNDGQ+0WSBBpbDwCgwaFy XtSM4QngCYEOJcjwXwL7tZQ=lPYq -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
This update fixes CVE-2015-1856, unauthorized deletion of versioned Swift object.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-12245 2015-07-29 21:42:30 -------------------------------------------------------------------------------- Name : openstack-swift Product : Fedora 22 Version : 2.2.0 Release : 5.fc22 URL : https://launchpad.net/swift Summary : OpenStack Object Storage (Swift) Description : OpenStack Object Storage (Swift) aggregates commodity servers to work together in clusters for reliable, redundant, and large-scale storage of static objects. Objects are written to multiple hardware devices in the data center, with the OpenStack software responsible for ensuring data replication and integrity across the cluster. Storage clusters can scale horizontally by adding new nodes, which are automatically configured. Should a node fail, OpenStack works to replicate its content from other active nodes. Because OpenStack uses software logic to ensure data replication and distribution across different devices, inexpensive commodity hard drives and servers can be used in lieu of more expensive equipment. -------------------------------------------------------------------------------- Update Information: This update fixes CVE-2015-1856, unauthorized deletion of versioned Swift object. -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 28 2015 Pete Zaitcev 2.2.0-5 - CVE-2015-1856, unauthorized deletion of versioned Swift object -------------------------------------------------------------------------------- References: [ 1 ] Bug #1246358 - CVE-2015-1856 openstack-swift: OpenStack Swift: unauthorized deletion of versioned Swift object [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1246358 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update openstack-swift' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Moderate security. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-swift security update Advisory ID: RHSA-2015:0835-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2015:0835.html Issue date: 2015-04-16 CVE Names: CVE-2014-7960 ==================================================================== 1. Summary: Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 7 - noarch 3. Description: OpenStack Object Storage (swift) provides object storage in virtual containers, which allows users to store and retrieve files (arbitrary data). The service's distributed architecture supports horizontal scaling; redundancy as failure-proofing is provided through software-based data replication. Because Object Storage supports asynchronous eventual consistency replication, it is well suited to multiple data-center deployment. A flaw was found in the metadata constraints in OpenStack Object Storage (swift). By adding metadata in several separate calls, a malicious user could bypass the max_meta_count constraint, and store more metadata than allowed by the configuration. (CVE-2014-7960) All users of openstack-swift are advised toupgrade to these updated packages, which correct this issue. After installing this update, the OpenStack Object Storage services will be restarted automatically. 4. Solution: Before applying this update, ensure all previously released errata relevant to your system have been applied. Red Hat Enterprise Linux OpenStack Platform 5 for RHEL 7 runs on Red Hat Enterprise Linux 7.1. The Red Hat Enterprise Linux OpenStack Platform 5 for RHEL 7 Release Notes contain the following: * An explanation of the way in which the provided components interact to form a working cloud computing environment. * Technology Previews, Recommended Practices, and Known Issues. * The channels required for Red Hat Enterprise Linux OpenStack Platform 5 for RHEL 7, including which channels need to be enabled and disabled. The Release Notes are linked to in the References section. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1150461 - CVE-2014-7960 openstack-swift: Swift metadata constraints are not correctly enforced 6. Package List: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 7: Source: openstack-swift-1.13.1-4.el7ost.src.rpm noarch: openstack-swift-1.13.1-4.el7ost.noarch.rpm openstack-swift-account-1.13.1-4.el7ost.noarch.rpm openstack-swift-container-1.13.1-4.el7ost.noarch.rpm openstack-swift-doc-1.13.1-4.el7ost.noarch.rpm openstack-swift-object-1.13.1-4.el7ost.noarch.rpm openstack-swift-proxy-1.13.1-4.el7ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2014-7960 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iD8DBQFVMAX0XlSAg2UNWIIRAs8+AJ9HdGcfwEgJcDdzkA8IVIGnkN5OkgCeLowj 664UfkbTMnChHuLOwgQzb9k=NIk1 -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for Red Hat Enterprise Linux 7. [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-swift security update Advisory ID: RHSA-2014:0941-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2014:0941.html Issue date: 2014-07-24 CVE Names: CVE-2014-3497 ==================================================================== 1. Summary: Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for Red Hat Enterprise Linux 7. The Red Hat Security Response Team has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: OpenStack 5.0 for RHEL 7 - noarch 3. Description: OpenStack Object Storage (Swift) provides object storage in virtual containers, which allows users to store and retrieve files (arbitrary data). It was found that Swift did not escape all HTTP header values, allowing data to be injected into the responses sent from the Swift server. This could lead to cross-site scripting attacks (and possibly other impacts) if a user were tricked into clicking on a malicious URL. (CVE-2014-3497) Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges the Globo.com Security Team as the original reporter. All users of openstack-swift are advised to upgrade to these updated packages, which correct this issue. After installing this update, the OpenStack Object Storage services will be restarted automatically. 4. Solution: Before applying this update, make sure allpreviously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1110809 - CVE-2014-3497 openstack-swift: XSS in Swift requests through WWW-Authenticate header 6. Package List: OpenStack 5.0 for RHEL 7: Source: openstack-swift-1.13.1-3.el7ost.src.rpm python-swiftclient-2.1.0-2.el7ost.src.rpm noarch: openstack-swift-1.13.1-3.el7ost.noarch.rpm openstack-swift-account-1.13.1-3.el7ost.noarch.rpm openstack-swift-container-1.13.1-3.el7ost.noarch.rpm openstack-swift-doc-1.13.1-3.el7ost.noarch.rpm openstack-swift-object-1.13.1-3.el7ost.noarch.rpm openstack-swift-proxy-1.13.1-3.el7ost.noarch.rpm python-swiftclient-2.1.0-2.el7ost.noarch.rpm python-swiftclient-doc-2.1.0-2.el7ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2014-3497 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2014 Red Hat, Inc. . Red Hat has released a vital security patch for openstack-swift, significantly reducing cross-site scripting (XSS) risks in Object Storage for OpenStack users. Red Hat OpenStack, Swift Security Update, Cross-Site Scripting, OpenStack Patch. . LinuxSecurity.com Team
Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 3.0. The Red Hat Security Response Team has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-swift security update Advisory ID: RHSA-2014:0367-01 Product: Red Hat OpenStack Advisory URL: https://access.redhat.com/errata/RHSA-2014:0367.html Issue date: 2014-04-03 CVE Names: CVE-2014-0006 ==================================================================== 1. Summary: Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 3.0. The Red Hat Security Response Team has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: OpenStack 3 - noarch 3. Description: OpenStack Object Storage (swift) provides object storage in virtual containers, which allows users to store and retrieve files (arbitrary data). The service's distributed architecture supports horizontal scaling; redundancy as failure-proofing is provided through software-based data replication. Because Object Storage supports asynchronous eventual consistency replication, it is well suited to multiple data-center deployment. A timing attack flaw was found in the way the swift TempURL middleware responded to arbitrary TempURL requests. An attacker with knowledge of an object's name could use this flaw to obtain a secret URL to this object, which was intended to be publicly shared only with specific recipients, if the object had the TempURL key set. Note that only setups usingthe TempURL middleware were affected. (CVE-2014-0006) Red Hat would like to thank the OpenStack Project for reporting this issue. Upstream acknowledges Samuel Merritt of SwiftStack as the original reporter. All users of openstack-swift are advised to upgrade to these updated packages, which correct this issue. After installing this update, the OpenStack Object Storage services will be restarted automatically. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1051670 - CVE-2014-0006 Openstack Swift: TempURL timing attack 6. Package List: OpenStack 3: Source: noarch: openstack-swift-1.8.0-8.el6ost.noarch.rpm openstack-swift-account-1.8.0-8.el6ost.noarch.rpm openstack-swift-container-1.8.0-8.el6ost.noarch.rpm openstack-swift-doc-1.8.0-8.el6ost.noarch.rpm openstack-swift-object-1.8.0-8.el6ost.noarch.rpm openstack-swift-proxy-1.8.0-8.el6ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2014-0006 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2014 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFTPdB6XlSAg2UNWIIRAjmIAJ9asnnQMVMq8arez+wjhsg+yPv+5QCfc5pD OUYTTMNO/XJJCAYRtYC+jOA=KwDx -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 4.0. The Red Hat Security Response Team has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-swift security update Advisory ID: RHSA-2014:0232-01 Product: Red Hat OpenStack Advisory URL: https://access.redhat.com/errata/RHSA-2014:0232.html Issue date: 2014-03-04 CVE Names: CVE-2014-0006 ==================================================================== 1. Summary: Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 4.0. The Red Hat Security Response Team has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: OpenStack 4 - noarch 3. Description: OpenStack Object Storage (swift) provides object storage in virtual containers, which allows users to store and retrieve files (arbitrary data). The service's distributed architecture supports horizontal scaling; redundancy as failure-proofing is provided through software-based data replication. Because Object Storage supports asynchronous eventual consistency replication, it is well suited to multiple data-center deployment. A timing attack flaw was found in the way the swift TempURL middleware responded to arbitrary TempURL requests. An attacker with knowledge of an object's name could use this flaw to obtain a secret URL to this object, which was intended to be publicly shared only with specific recipients, if the object had the TempURL key set. Note that only setups usingthe TempURL middleware were affected. (CVE-2014-0006) Red Hat would like to thank the Openstack Project for reporting this issue. Upstream acknowledges Samuel Merritt of SwiftStack as the original reporter. All users of openstack-swift are advised to upgrade to these updated packages, which correct this issue. After installing this update, the OpenStack Object Storage services will be restarted automatically. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1051670 - CVE-2014-0006 Openstack Swift: TempURL timing attack 6. Package List: OpenStack 4: Source: noarch: openstack-swift-1.10.0-3.el6ost.noarch.rpm openstack-swift-account-1.10.0-3.el6ost.noarch.rpm openstack-swift-container-1.10.0-3.el6ost.noarch.rpm openstack-swift-doc-1.10.0-3.el6ost.noarch.rpm openstack-swift-object-1.10.0-3.el6ost.noarch.rpm openstack-swift-proxy-1.10.0-3.el6ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2014-0006 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2014 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFTFip6XlSAg2UNWIIRAo6pAJwPy3nfKn4SPNO5u+8rNpRbtBnrXwCfZZsF qHpypUHyvx3KkcU7IVIBPI4=EwJL -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Get the latest Linux and open source security news straight to your inbox.