Bug 974271 (CVE-2013-2166, CVE-2013-2167)
| Summary: | CVE-2013-2166 CVE-2013-2167 python-keystoneclient: middleware memcache encryption and signing bypass | ||||||
|---|---|---|---|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Kurt Seifried <kseifried> | ||||
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||
| Status: | CLOSED ERRATA | QA Contact: | |||||
| Severity: | high | Docs Contact: | |||||
| Priority: | high | ||||||
| Version: | unspecified | CC: | aortega, apevec, ayoung, chrisw, gmollett, iheim, jkt, jrusnack, jruzicka, markmc, rbryant, sclewis, security-response-team | ||||
| Target Milestone: | --- | Keywords: | Security | ||||
| Target Release: | --- | ||||||
| Hardware: | All | ||||||
| OS: | Linux | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | Doc Type: | Bug Fix | |||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2014-11-06 05:54:48 UTC | Type: | --- | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Bug Depends On: | 974273, 974274, 974275, 976024, 976025 | ||||||
| Bug Blocks: | 974276 | ||||||
| Attachments: |
|
||||||
|
Description
Kurt Seifried
2013-06-13 19:49:46 UTC
In general the memcached for OpenStack (and any memcached deployment generally speaking) should be restricted to trusted systems due to the lack of authentication in memcached. However the signing/encryption of data within memcached is an attempt to alleviate this problems so systems using these capabilities may have exposed memcached to untrusted systems. Created attachment 760946 [details]
client-CVE-2013-2166-CVE-2013-2167.patch
Red Hat OpenStack 1 (Essex) and 2.1 (Folsom) do not contain the affected code and are not affected as such. THIs is now public http://openwall.com/lists/oss-security/2013/06/19/5 Created python-keystoneclient tracking bugs for this issue Affects: epel-6 [bug 976024] Created python-keystoneclient tracking bugs for this issue Affects: fedora-all [bug 976025] Acknowledgements: Red Hat would like to thank the OpenStack project for reporting these issues. Upstream acknowledges Paul McMillan of Nebula as the original reporter. This issue has been addressed in following products: OpenStack 3 for RHEL 6 Via RHSA-2013:0992 https://rhn.redhat.com/errata/RHSA-2013-0992.html python-keystoneclient-0.2.3-7.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report. |