Updated openstack-swift packages that fix two security issues are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6. Red Hat Product Security has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-swift security update Advisory ID: RHSA-2016:0126-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2016:0126.html Issue date: 2016-02-08 CVE Names: CVE-2016-0737 CVE-2016-0738 ==================================================================== 1. Summary: Updated openstack-swift packages that fix two security issues are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6. Red Hat Product Security has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6 - noarch 3. Description: OpenStack Object Storage (swift) provides object storage in virtual containers, which allows users to store and retrieve files (arbitrary data). The service's distributed architecture supports horizontal scaling; redundancy as failure-proofing is provided through software-based data replication. Because Object Storage supports asynchronous eventual consistency replication, it is well suited to multiple data-center deployment. A memory-leak issue was found in OpenStack Object Storage (swift), in the proxy-to-server connection. An OpenStack-authenticated attacker could remotely trigger this flaw to cause denial of service through excess memory consumption. (CVE-2016-0738) A memory-leak issuewas found in OpenStack Object Storage (swift), in the client-to-proxy connection. An OpenStack-authenticated attacker could remotely trigger this flaw to cause denial of service through excess memory consumption. (CVE-2016-0737) Red Hat would like to thank the OpenStack project for reporting these issues. Upstream acknowledges Romain Le Disez from OVH and Örjan Persson from Kiliaro as the original reporters. All users of openstack-swift are advised to upgrade to these updated packages, which correct these issues. After installing this update, the OpenStack Object Storage services will be restarted automatically. 4. Solution: Before applying this update, ensure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1298905 - CVE-2016-0738 openstack-swift: Proxy to server DoS through Large Objects 1298924 - CVE-2016-0737 openstack-swift: Client to proxy DoS through Large Objects 6. Package List: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6: Source: openstack-swift-1.13.1-8.el6ost.src.rpm noarch: openstack-swift-1.13.1-8.el6ost.noarch.rpm openstack-swift-account-1.13.1-8.el6ost.noarch.rpm openstack-swift-container-1.13.1-8.el6ost.noarch.rpm openstack-swift-doc-1.13.1-8.el6ost.noarch.rpm openstack-swift-object-1.13.1-8.el6ost.noarch.rpm openstack-swift-proxy-1.13.1-8.el6ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2016-0737 https://access.redhat.com/security/cve/CVE-2016-0738 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2016 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iD8DBQFWuB1RXlSAg2UNWIIRAks2AJ0U8AAwBV0ZBajdj8khFy//ltR7WQCgwAHM q/qYsJt2iVIDRbBgT0+sDH4=SSw9 -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available.. SUSE Security Update: Security update for openstack-swift ______________________________________________________________________________ Announcement ID: SUSE-SU-2015:1846-1 Rating: important References: #900253 #927793 #942641 Cross-References: CVE-2014-7960 CVE-2015-1856 CVE-2015-5223 Affected Products: SUSE OpenStack Cloud 5 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: openstack-swift was updated to fix three security issues. These security issues were fixed: - CVE-2015-1856: OpenStack Object Storage (Swift), when allow_version is configured, allowed remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container (bsc#927793). - CVE-2014-7960: OpenStack Object Storage (Swift) allowed remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined (bsc#900253). - CVE-2015-5223: Information leak via Swift tempurls (bsc#942641). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 5: zypper in -t patch sleclo50sp3-openstack-swift-12171=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE OpenStack Cloud 5 (x86_64): openstack-swift-2.1.0-11.1 openstack-swift-account-2.1.0-11.1 openstack-swift-container-2.1.0-11.1 openstack-swift-object-2.1.0-11.1 openstack-swift-proxy-2.1.0-11.1 python-swift-2.1.0-11.1 - SUSE OpenStack Cloud 5 (noarch): openstack-swift-doc-2.1.0-11.1 References: https://www.suse.com/security/cve/CVE-2014-7960.html https://www.suse.com/security/cve/CVE-2015-1856.html https://www.suse.com/security/cve/CVE-2015-5223.html https://bugzilla.suse.com/900253 https://bugzilla.suse.com/927793 https://bugzilla.suse.com/942641 . SUSE Security Patch for openstack-nova: critical resolutions for vulnerabilities in SUSE OpenStack Cloud 5 have been released.. OpenStack Swift Updates, SUSE Cloud Security, Linux Updates. . Severity: Important. LinuxSecurity.com Team
Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0, 6.0, and 7.0. Red Hat Product Security has rated this update as having Moderate security. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-swift security update Advisory ID: RHSA-2015:1895-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2015:1895.html Issue date: 2015-10-15 CVE Names: CVE-2015-5223 ==================================================================== 1. Summary: Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0, 6.0, and 7.0. Red Hat Product Security has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6 - noarch Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 7 - noarch Red Hat Enterprise Linux OpenStack Platform 6.0 for RHEL 7 - noarch Red Hat Enterprise Linux OpenStack Platform 7.0 for RHEL 7 - noarch 3. Description: OpenStack Object Storage (swift) provides object storage in virtual containers, which allows users to store and retrieve files (arbitrary data). The service's distributed architecture supports horizontal scaling; redundancy as failure-proofing is provided through software-based data replication. Because Object Storage supports asynchronous eventual consistency replication, it is well suited to deployment in multiple data centers. A flaw was found in the OpenStack Object storage service (swift) tempurls. An attacker in possession of a tempurl key with PUTpermissions may be able to gain read access to other objects in the same project. (CVE-2015-5223) Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Richard Hawkins of Rackspace, and the OpenStack Swift core reviewers as the original reporters. All users of openstack-swift are advised to upgrade to these updated packages, which correct this issue. After installing this update, the OpenStack Object Storage services will be restarted automatically. 4. Solution: Before applying this update, ensure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1255622 - CVE-2015-5223 openstack-swift: Information leak via Swift tempurls 6. Package List: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6: Source: openstack-swift-1.13.1-7.el6ost.src.rpm noarch: openstack-swift-1.13.1-7.el6ost.noarch.rpm openstack-swift-account-1.13.1-7.el6ost.noarch.rpm openstack-swift-container-1.13.1-7.el6ost.noarch.rpm openstack-swift-doc-1.13.1-7.el6ost.noarch.rpm openstack-swift-object-1.13.1-7.el6ost.noarch.rpm openstack-swift-proxy-1.13.1-7.el6ost.noarch.rpm Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 7: Source: openstack-swift-1.13.1-7.el7ost.src.rpm noarch: openstack-swift-1.13.1-7.el7ost.noarch.rpm openstack-swift-account-1.13.1-7.el7ost.noarch.rpm openstack-swift-container-1.13.1-7.el7ost.noarch.rpm openstack-swift-doc-1.13.1-7.el7ost.noarch.rpm openstack-swift-object-1.13.1-7.el7ost.noarch.rpm openstack-swift-proxy-1.13.1-7.el7ost.noarch.rpm Red Hat Enterprise Linux OpenStack Platform 6.0 for RHEL7: Source: openstack-swift-2.2.0-5.el7ost.src.rpm noarch: openstack-swift-2.2.0-5.el7ost.noarch.rpm openstack-swift-account-2.2.0-5.el7ost.noarch.rpm openstack-swift-container-2.2.0-5.el7ost.noarch.rpm openstack-swift-doc-2.2.0-5.el7ost.noarch.rpm openstack-swift-object-2.2.0-5.el7ost.noarch.rpm openstack-swift-proxy-2.2.0-5.el7ost.noarch.rpm Red Hat Enterprise Linux OpenStack Platform 7.0 for RHEL 7: Source: openstack-swift-2.3.0-2.el7ost.src.rpm noarch: openstack-swift-2.3.0-2.el7ost.noarch.rpm openstack-swift-account-2.3.0-2.el7ost.noarch.rpm openstack-swift-container-2.3.0-2.el7ost.noarch.rpm openstack-swift-doc-2.3.0-2.el7ost.noarch.rpm openstack-swift-object-2.3.0-2.el7ost.noarch.rpm openstack-swift-proxy-2.3.0-2.el7ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-5223 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFWIBEYXlSAg2UNWIIRAt4TAKCu+wyoa7hH69PYJ3t7pvoTjH32WgCeOgXq duNcJH7cjNqdCsipqt897SQ=qfKo -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0. Red Hat Product Security has rated this update as having Moderate security [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-swift security update Advisory ID: RHSA-2015:1684-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2015:1684.html Issue date: 2015-08-25 CVE Names: CVE-2015-1856 ==================================================================== 1. Summary: Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0. Red Hat Product Security has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6 - noarch Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 7 - noarch 3. Description: OpenStack Object Storage (swift) provides object storage in virtual containers, which allows users to store and retrieve files (arbitrary data). The service's distributed architecture supports horizontal scaling; redundancy as failure-proofing is provided through software-based data replication. Because Object Storage supports asynchronous eventual consistency replication, it is well suited to multiple data-center deployment. A flaw was found in OpenStack Object Storage that could allow an authenticated user to delete the most recent version of a versioned object regardless of ownership. To exploit this flaw, an attacker must know the name of the object and have listing access to the x-versions-location container. (CVE-2015-1856) Red Hat would like to thankthe OpenStack project for reporting this issue. Upstream acknowledges Clay Gerrard of SwiftStack as the original reporter. All users of openstack-swift are advised to upgrade to these updated packages, which correct this issue. After installing this update, the OpenStack Object Storage services will be restarted automatically. 4. Solution: Before applying this update, ensure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1209994 - CVE-2015-1856 OpenStack Swift: unauthorized deletion of versioned Swift object 6. Package List: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6: Source: openstack-swift-1.13.1-6.el6ost.src.rpm noarch: openstack-swift-1.13.1-6.el6ost.noarch.rpm openstack-swift-account-1.13.1-6.el6ost.noarch.rpm openstack-swift-container-1.13.1-6.el6ost.noarch.rpm openstack-swift-doc-1.13.1-6.el6ost.noarch.rpm openstack-swift-object-1.13.1-6.el6ost.noarch.rpm openstack-swift-proxy-1.13.1-6.el6ost.noarch.rpm Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 7: Source: openstack-swift-1.13.1-5.el7ost.src.rpm noarch: openstack-swift-1.13.1-5.el7ost.noarch.rpm openstack-swift-account-1.13.1-5.el7ost.noarch.rpm openstack-swift-container-1.13.1-5.el7ost.noarch.rpm openstack-swift-doc-1.13.1-5.el7ost.noarch.rpm openstack-swift-object-1.13.1-5.el7ost.noarch.rpm openstack-swift-proxy-1.13.1-5.el7ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-1856 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. . Red Hat has released a security advisory regarding asignificant vulnerability in OpenStack Swift affecting object storage management, urging immediate reviews and updates.. Red Hat OpenStack, Object Storage Security, OpenStack Swift Update. . LinuxSecurity.com Team
Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for Red Hat Enterprise Linux 6. [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-swift security update Advisory ID: RHSA-2015:0836-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2015:0836.html Issue date: 2015-04-16 CVE Names: CVE-2014-7960 ==================================================================== 1. Summary: Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6 - noarch 3. Description: OpenStack Object Storage (swift) provides object storage in virtual containers, which allows users to store and retrieve files (arbitrary data). The service's distributed architecture supports horizontal scaling; redundancy as failure-proofing is provided through software-based data replication. Because Object Storage supports asynchronous eventual consistency replication, it is well suited to multiple data-center deployment. A flaw was found in the metadata constraints in OpenStack Object Storage (swift). By adding metadata in several separate calls, a malicious user could bypass the max_meta_count constraint, and store more metadata than allowed by the configuration. (CVE-2014-7960) All users of openstack-swift are advised to upgrade to these updated packages, which correct this issue. After installing this update, the OpenStack ObjectStorage services will be restarted automatically. 4. Solution: Before applying this update, ensure all previously released errata relevant to your system have been applied. Red Hat Enterprise Linux OpenStack Platform 5 for RHEL 6 runs on Red Hat Enterprise Linux 6.6. The Red Hat Enterprise Linux OpenStack Platform 5 for RHEL 6 Release Notes contain the following: * An explanation of the way in which the provided components interact to form a working cloud computing environment. * Technology Previews, Recommended Practices, and Known Issues. * The channels required for Red Hat Enterprise Linux OpenStack Platform 5 for RHEL 6, including which channels need to be enabled and disabled. The Release Notes are linked to in the References section. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1150461 - CVE-2014-7960 openstack-swift: Swift metadata constraints are not correctly enforced 6. Package List: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6: Source: openstack-swift-1.13.1-4.el6ost.src.rpm noarch: openstack-swift-1.13.1-4.el6ost.noarch.rpm openstack-swift-account-1.13.1-4.el6ost.noarch.rpm openstack-swift-container-1.13.1-4.el6ost.noarch.rpm openstack-swift-doc-1.13.1-4.el6ost.noarch.rpm openstack-swift-object-1.13.1-4.el6ost.noarch.rpm openstack-swift-proxy-1.13.1-4.el6ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2014-7960 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2015 Red Hat, Inc. . Recent updates to openstack-swift address a major security vulnerability for users of Red Hat Enterprise Linux OpenStack. Discover additional details!.Openstack Swift, Red Hat Update, Object Storage Security. . LinuxSecurity.com Team
OpenStack Swift would allow unintended access to files over the network.. =========================================================================Ubuntu Security Notice USN-2207-1 May 06, 2014 swift vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 13.10 - Ubuntu 12.10 - Ubuntu 12.04 LTS Summary: OpenStack Swift would allow unintended access to files over the network. Software Description: - swift: OpenStack distributed virtual object store Details: Samuel Merritt discovered a timing attack vulnerability in OpenStack Swift. If Swift was configured to use the TempURL middleware, an attacker could exploit this to guess valid secret URLs and obtain unintended access to objects publicly shared with specific recipients. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 13.10: python-swift 1.10.0-0ubuntu1.1 Ubuntu 12.10: python-swift 1.7.4-0ubuntu2.4 Ubuntu 12.04 LTS: python-swift 1.4.8-0ubuntu2.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2207-1 CVE-2014-0006 Package Information: https://launchpad.net/ubuntu/+source/swift/1.10.0-0ubuntu1.1 https://launchpad.net/ubuntu/+source/swift/1.7.4-0ubuntu2.4 https://launchpad.net/ubuntu/+source/swift/1.4.8-0ubuntu2.4 . OpenStack Swift flaw exposes unauthorized file access. Upgrade Ubuntu to address crucial security threat.. OpenStack Swift, File Access, Security Update. . Severity: Important. LinuxSecurity.com Team
Multiple security issues were fixed in OpenStack Swift.. =========================================================================Ubuntu Security Notice USN-1887-1 June 20, 2013 swift vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 13.04 - Ubuntu 12.10 - Ubuntu 12.04 LTS Summary: Multiple security issues were fixed in OpenStack Swift. Software Description: - swift: OpenStack distributed virtual object store Details: Sebastian Krahmer discovered that Swift used the loads function in the pickle Python module when it was configured to use memcached. A remote attacker on the same network as memcached could exploit this to execute arbitrary code. This update adds a new memcache_serialization_support option to support secure json serialization. For details on this new option, please see /usr/share/doc/swift-proxy/memcache.conf-sample. This issue only affected Ubuntu 12.04 LTS. (CVE-2012-4406) Alex Gaynor discovered that Swift did not safely generate XML. An attacker could potentially craft an account name to generate arbitrary XML responses to trigger vulnerabilties in software parsing Swift's XML. (CVE-2013-2161) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 13.04: python-swift 1.8.0-0ubuntu1.2 Ubuntu 12.10: python-swift 1.7.4-0ubuntu2.2 Ubuntu 12.04 LTS: python-swift 1.4.8-0ubuntu2.2 After a standard system update you need to restart Swift to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1887-1 CVE-2012-4406, CVE-2013-2161 Package Information: https://launchpad.net/ubuntu/+source/swift/1.8.0-0ubuntu1.2 https://launchpad.net/ubuntu/+source/swift/1.7.4-0ubuntu2.2 https://launchpad.net/ubuntu/+source/swift/1.4.8-0ubuntu2.2 . Numerousconcerns addressed in OpenStack Swift for Ubuntu, featuring vital corrections and secure programming methodologies.. OpenStack Security, Python Swift Update, Remote Execution Risk. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.