Ubuntu has issued an advisory on June 3: http://www.ubuntu.com/usn/usn-1851-1/ Mageia 3 is also affected, as this package wasn't deleted with the rest of the openstack stuff before the release was branched. Reproducible: Steps to Reproduce:
Whiteboard: (none) => MGA3TOO
I think I've got the patch, can you confirm? https://review.openstack.org/#/c/30742/
(In reply to Sandro Cazzaniga from comment #1) > I think I've got the patch, can you confirm? > > https://review.openstack.org/#/c/30742/ If I try to view the diff on that page, it just seems to go into an infinite loop opening new tabs in my browser O_O. Ubuntu has a link to the upstream patch at the bottom of this page: http://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-2104.html
Got it: https://review.openstack.org/gitweb?p=openstack%2Fkeystone.git;a=commitdiff;h=8d23da1302dde9d38bbc227d9aba30da919b60c8 I apply and test ASAP.
OpenSuSE has issued an advisory on June 27: http://lists.opensuse.org/opensuse-updates/2013-06/msg00199.html from http://lwn.net/Vulnerabilities/556766/ This adds an additional CVE, CVE-2013-2013.
Summary: python-keystoneclient new security issue CVE-2013-2104 => python-keystoneclient new security issues CVE-2013-2104 and CVE-2013-2013
RedHat has issued an advisory on June 27: https://rhn.redhat.com/errata/RHSA-2013-0992.html from http://lwn.net/Vulnerabilities/556768/ This adds two additional CVEs, CVE-2013-2166 and CVE-2013-2167.
Summary: python-keystoneclient new security issues CVE-2013-2104 and CVE-2013-2013 => python-keystoneclient new security issues CVE-2013-2104, CVE-2013-2013, CVE-2013-2166, CVE-2013-2167
Assignee: cazzaniga.sandro => nicolas.lecureuil
this is for cauldron ?
Well, the package had been removed from Cauldron, but unfortunately it looks like you're bringing it back. Anyway, this package was *supposed* to have been removed from Mageia 3 before release, but was missed, so a version of this package with all of these security vulnerabilities exists in Mageia 3.
i will look w/o pb
Package is no longer in Cauldron. This package is not supported in Mageia 3 and slipped in by accident. Closing as WONTFIX.
Status: NEW => RESOLVEDVersion: Cauldron => 3Resolution: (none) => WONTFIXWhiteboard: MGA3TOO => (none)