Friday, October 25, 2013

Announcing the Fedora Server Working Group

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

tl;dr The Server Working Group has been formed and will be meeting on
Wednesday. See the == Logistical Information == section below for details.


== General Announcement ==

As most of you are aware, the Fedora Project is embarking upon a new
venture. Traditionally, the Fedora Project has been a "bag of bits"
collection of packages that attempted to serve everyone's needs
simulataneously. As time has passed, we've discovered that when you
try to please everyone at once, you usually fail to please anyone at all.

Starting at Flock, a new proposal was born: Instead of One Fedora
Project to Rule Them All, why don't we try building three Fedora
Operating Systems from the packages in the Fedora Project. These three
operating systems (dubbed Fedora Server, Fedora Workstation and Fedora
Cloud, initially) were discussed at length, then ultimately proposed
to the Fedora Project Advisory Board, who gave the go-ahead to start
implementation.

We spent about a month eliciting calls for volunteers to serve on five
"Working Groups". There is one group built around the planning and
execution of each of these new Fedora Products and then the "Base
Design" group, which will be responsible for ensuring that the
products share a common core and an "Environments and Stacks" group
that will investigate how best to deploy software from the larger
Fedora Project ecosystem atop these new Fedora Products.

Part of the planning process for these new working groups was for us
to set up an initial voting membership who has two initial
responsibilities[1]:
1) Establish a governance charter - determine how to run the Working
Group and elect voting members. This charter is due on November 15,
2013 and must be ratified by FESCo.
2) Produce a Product Requirements Document (PRD) - This is a statement
of target audience and the role of the project (what problems it
will solve and what niche it will fill). This is a high-level view
of the Product. This document is due in January, 2014 and must be
ratified by the Fedora Advisory Board.

To talk a little bit about the voting membership. It should be noted
that these are NOT the only members of the Server WG that can
participate. We strongly encourage the participation of all of the
larger Server SIG in this effort. Ultimately, the voting membership
will be the ones to make (and vote on) final decisions, particularly
in the case of controversy or disagreement. This should never be done
without careful consideration of all the facts.

The initial voting membership was selected by the FESCo coordinator
(me, Stephen Gallagher).

* Jim Perrin: He will bring to the table an idea of what the CentOS
project would want to see in CentOS 8 for its constituency (which is
notably different from Red Hat's consumers, despite sharing a common
code ancestry)

* David Strauss: He maintains a large existing deployment of Fedora
servers in production and will be able to help us identify its
strengths and weaknesses when used in such a manner.

* Truong Anh. Tuan: Representing the Fedora Ambassadors, he will be
aiding us in producing information that will be useful when talking
about this new product in public.

* Máirín Duffy: As the representative from the Fedora Design Team, she
will be invaluable in all conversations planning for the user
experience and product announcements.

* Kevin Fenzi: Representing Fedora Infrastructure, he will hopefully
keep us grounded in what we can or cannot accomplish in a particular
period of time (as well as having a wealth of knowledge around
real-world deployment scenarios). He is also a member of FESCo,
though not acting as coordinator.

* Miloslav Trmač: Red Hat security engineer who no doubt work
tirelessly to ensure that we ship a product that is tightly
controlled and properly maintained, as well as representing other
low-level security decisions. He is also a member of FESCo, though
not acting as coordinator.

* Simo Sorce: Red Hat engineer representing the identity and policy
management space. His experience with both FreeIPA and Active
Directory will be invaluable as we work out how to coordinate Fedora
Server in heterogenous environments.

* Jóhann B. Guðmundsson: Representing the Fedora QA team, I expect
Jóhann to focus primarily on working to make sure that we do not
make life any more difficult for testers than we strictly must.


== Logistical Information ==

This logistical information is a proposal. We may decide to change
some or all of it as a result of the first meeting of the voting
membership.

This meeting will take place in #fedora-meeting-1 on Wednesday,
November 30 at 17:00 UTC (13:00 EDT, 19:00 CZ). This is immediately
prior to the FESCo meeting at 18:00 UTC, so we will have a strict
one-hour limit on this meeting.

Mailing List: server@lists.fedoraproject.org
IRC Channel: #fedora-server on Freenode

[1]
https://fedoraproject.org/wiki/Fedora.next/boardproposal#Product_Working_Groups
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.15 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iEYEARECAAYFAlJqX8gACgkQeiVVYja6o6MGfwCfZbtEQaE1sia1VzUqgBhnmPRZ
fUkAnRDpZhX5n6CxIRDNsOjhOZL9fWfz
=JsL9
-----END PGP SIGNATURE-----
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel-announce

Thursday, October 24, 2013

[USN-2007-1] Apport vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSaWO8AAoJEGVp2FWnRL6TDyMP/1Piav7YTF+Oxgg5DK1sg+hI
R+XuIyFjp81KcaZpBJI/qD+yXtDvi+oNvtQHxAuF3CT5i4eoCsEhiL4jYOcWTjlu
+zkVWHq2xcWGfIsUDks/nL/0wXMy7wwSpiV8Lb1ejRV8Z310e/y69kEhSUIslyQU
iAigoaWxvp45uhIlvqSv6jlIx8QgZw0U7nND1XOGPWvN482kyh8f7K+AvjIRePmd
hNTbgeahD4iF8EI5gVHLWmiHAUwxqhorRJgJSSECIZRvSd17+pIfW/o5QfpG3ZX5
fr9X23QVJxNY14Jt4WpKuXajl55yT6E0WHS4C9pWbFijClTwaKKp28LnDsqgEZjU
pkshfhQrKjkK0yvHzvPrTrXv1nVvvXoDokoZnnSRJBDV6QgAeRAZaD9quEAxYdXV
S/uEB5U5IdAmw5DGDqXXePp0QJ7BeY/pY3QdYBbn2eW6lOEyZ1eH6C+fxY0eCErf
4R4NvBqTmcKEJkG7XPlUDwXn4DrcsPlRroAlNwongOl3eHgy//Ecsy3CsMZnxjoM
uhaAWZ74ZbNlsCuumaxay/TFjabQrIycHF5eEMBzVNWd0967SgVq5v3y0jK85My+
no+VwP7qsh8pHYdTc911xxTYiRUP/qbEKpK7acD70eF3Wc8bh81c+LxKSwezO0oa
/BOMk843vPcq5E3KZUgN
=hBh/
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2007-1
October 24, 2013

apport vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.10
- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS

Summary:

Apport could be made to expose privileged information.

Software Description:
- apport: automatically generate crash reports for debugging

Details:

Martin Carpenter discovered that Apport set incorrect permissions on core
dump files generated by setuid binaries. A local attacker could possibly
use this issue to obtain privileged information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
apport 2.12.5-0ubuntu2.1

Ubuntu 13.04:
apport 2.9.2-0ubuntu8.5

Ubuntu 12.10:
apport 2.6.1-0ubuntu13

Ubuntu 12.04 LTS:
apport 2.0.1-0ubuntu17.6

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2007-1
CVE-2013-1067

Package Information:
https://launchpad.net/ubuntu/+source/apport/2.12.5-0ubuntu2.1
https://launchpad.net/ubuntu/+source/apport/2.9.2-0ubuntu8.5
https://launchpad.net/ubuntu/+source/apport/2.6.1-0ubuntu13
https://launchpad.net/ubuntu/+source/apport/2.0.1-0ubuntu17.6

[USN-2008-1] Suds vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSaWPPAAoJEGVp2FWnRL6TymQQAKylrPlPberaO0oXjbU0C2xj
VMiG0WeijeSxucQ5siYMyOLCrm23fd1SbuYDM8StrZOfr6rdIn5mroQ0BCRPBOww
pGt2dokokyPUc6GmOeZyzAQdP1ENPf2qq5y3vc3Nh2NwQmIg6r/2BLFuZ7N1DczJ
K2edPMs5RF/HWkv1QS4FbcNLGYypmX9JKElcvUakKP2ib4nXjfE3/7ZaeW7Dl6ie
4aXjggoBl4B1JjZbYSN/YpzPmrW6n+72zUVquUEQcLz2yve9VXt9YgoICzW1w7KX
hNUTAidHoqZbiJ9IFFqzq5p/8oWep4DSg3u00aAjk5Z1B+WhAt7HN4Or3siCgeqj
qhBdAAQRi0zLxoiDxLG4mTQVXTKPENPQ7VQvUwZcvdjcQJyL7F5n+W1vCBOqrh6p
8Z0IglV3dg++Q1KjJ7U5I8Vkr6IIDRH5bkQSrHwUKysI1h/SF2Osf3lRrWCAFPnR
8qov0ndNJnKWz3Or97h5/8EiZfBv6cBjJFUHay20JMAK/4+hJ0JPp0f+juqzVBnI
iDmzeObRt5p76irvz4e+GIzYv9OfC0cnGWscAzRaWe5N3IbFPa2sRyq4YvkKAUxc
ofu/uB6OOcU9qk6mDNPzs94l7T0mhK++BBpVVZO1bBfYZw546ir00G6Wg9xI6txg
Q6Q2OYvWTvTUiNHK6vOf
=caf5
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2008-1
October 24, 2013

suds vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS

Summary:

Suds could be made to overwrite files.

Software Description:
- suds: Lightweight SOAP client for Python

Details:

Ralph Loader discovered that Suds incorrectly handled temporary files. A
local attacker could possibly use this issue to overwrite arbitrary files.
In the default installation of Ubuntu, this should be prevented by the Yama
link restrictions.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
python-suds 0.4.1-5ubuntu0.13.04.1

Ubuntu 12.10:
python-suds 0.4.1-5ubuntu0.12.10.1

Ubuntu 12.04 LTS:
python-suds 0.4.1-2ubuntu1.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2008-1
CVE-2013-2217

Package Information:
https://launchpad.net/ubuntu/+source/suds/0.4.1-5ubuntu0.13.04.1
https://launchpad.net/ubuntu/+source/suds/0.4.1-5ubuntu0.12.10.1
https://launchpad.net/ubuntu/+source/suds/0.4.1-2ubuntu1.1

[USN-2006-1] MySQL vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSaWOqAAoJEGVp2FWnRL6TnJwP/R7NJ+PRpr8eDerGKZI8YQhv
sPAn+Q6vvdjMQI2ECJ5YaGL/chBRYlA39L0BYB1SDqLAjouuAKo7qLCNHCvFykH9
NzEzEsgStTXwOArCA4Vr+Ikt7K1K3C5tOUhXZSTK2vNPAs8ya1urpiSmhdA3vYWa
EaRVYRGmWF0oQgkk0gNwLYbXY753O16DLTiiUrobyy6CMrFJMZrSbUinA1m/hdKP
k1jEwBq+HJOrv5SHStpjN4a48Vu+wL0ImJ6UvZX3sopYAopRxJHh/ag4zwlKETTa
1r6VbTXd2Ti/G8b64NUsZ4swNyR2iD8Q6I99VkcElj/5j/X2kRd7RQNbvbXyQZ+D
sr5OLyCEUEKFXN8RyH3iXxOw3Z8LxWJbJ57YCaTNRHFPiFL7MobErqVPCj10dFbc
ewZp808JDHpsR7FyUMPLEc4OLj3AcVUuqpAoW2Ts3euBmYsymNEAS/+Yi6MwkN37
2Wn21imvytruatyVFMOYNLP+k0hKI/EX5qIfe0GuAG8g/rV6N2neHUZYY3tUKndH
8Ey5BN4dADwZc9xeghwaMQPnn9kpEO9A7qVgZqgwZRcWKp9ivlyqOsgbiwaBQNkW
QCA9cGefKH+OqnuLlHeYO2L8xt16qaqop0kSz5ri4zsH5U1v4LKtw1yDvNuEpotz
fknfeXbueyzO3IiEj/V3
=wJ2f
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2006-1
October 24, 2013

mysql-5.5, mysql-dfsg-5.1 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.10
- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS

Summary:

Several security issues were fixed in MySQL.

Software Description:
- mysql-5.5: MySQL database
- mysql-dfsg-5.1: MySQL database

Details:

Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.

MySQL has been updated to 5.1.72 in Ubuntu 10.04 LTS. Ubuntu 12.04 LTS,
Ubuntu 12.10, Ubuntu 13.04 and Ubuntu 13.10 have been updated to
MySQL 5.5.34.

In addition to security fixes, the updated packages contain bug fixes,
new features, and possibly incompatible changes.

Please see the following for more information:
http://dev.mysql.com/doc/relnotes/mysql/5.1/en/news-5-1-72.html
http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-34.html
http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
mysql-server-5.5 5.5.34-0ubuntu0.13.10.1

Ubuntu 13.04:
mysql-server-5.5 5.5.34-0ubuntu0.13.04.1

Ubuntu 12.10:
mysql-server-5.5 5.5.34-0ubuntu0.12.10.1

Ubuntu 12.04 LTS:
mysql-server-5.5 5.5.34-0ubuntu0.12.04.1

Ubuntu 10.04 LTS:
mysql-server-5.1 5.1.72-0ubuntu0.10.04.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2006-1
CVE-2013-3839, CVE-2013-5807

Package Information:
https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.34-0ubuntu0.13.10.1
https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.34-0ubuntu0.13.04.1
https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.34-0ubuntu0.12.10.1
https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.34-0ubuntu0.12.04.1
https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1/5.1.72-0ubuntu0.10.04.1

Fedora 20 Beta to slip by one week

Today at Go/No-Go meeting it was decided to slip Fedora 20 Beta release
by one week due to unresolved blocker bugs, see the blocker tracking app [1].
More details in meeting minutes [2].

As a result, ALL MAJOR MILESTONES, and their dependent tasks, will be
pushed out by one week [3]. The new Fedora 20 GA date is now Dec 10.

The next Go/No-Go meeting is on Thursday, Oct 31, the same time in
#fedora-meeting-2 channel.

[1] http://qa.fedoraproject.org/blockerbugs/milestone/20/beta/buglist
[2] http://meetbot.fedoraproject.org/fedora-meeting-1/2013-10-24/fedora-meeting-1.2013-10-24-16.09.html
[3] https://fedoraproject.org/wiki/Releases/20/Schedule
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel-announce

[CentOS-announce] CESA-2013:1459 Moderate CentOS 6 gnupg2 Update

CentOS Errata and Security Advisory 2013:1459 Moderate

Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1459.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
6aa89f96d1cfd8908fd626383bdc3b4c005791e2cd640f4f4378f927b4bf1f17 gnupg2-2.0.14-6.el6_4.i686.rpm
aaf1056582718786d36262f305ed609c7175ccc29c3dbe1875bd75f4c710b871 gnupg2-smime-2.0.14-6.el6_4.i686.rpm

x86_64:
71bc0bf467b5d366a6811846d2177f841de438ee60754f26dc57c1d3ab26cf23 gnupg2-2.0.14-6.el6_4.x86_64.rpm
3e90ca1a588ae05a452d271119e09a1d0c31e4bd3da230ee7ef498831d3e5b5e gnupg2-smime-2.0.14-6.el6_4.x86_64.rpm

Source:
44fcd477f37bc5265ff0632afd7fc43bd4545ab32456023cdaec32345c2d4561 gnupg2-2.0.14-6.el6_4.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2013:1457 Moderate CentOS 6 libgcrypt Update

CentOS Errata and Security Advisory 2013:1457 Moderate

Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1457.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
800d11a507a330b28e59d300bf7383b19c95b5a857863b1501b8aa1f0b9388dc libgcrypt-1.4.5-11.el6_4.i686.rpm
d97f0c12e08acb0844404a6ba4ab288d20dcf2a16d03bcf5647b05eba3e98f65 libgcrypt-devel-1.4.5-11.el6_4.i686.rpm

x86_64:
800d11a507a330b28e59d300bf7383b19c95b5a857863b1501b8aa1f0b9388dc libgcrypt-1.4.5-11.el6_4.i686.rpm
bdda38f5a6dbfe6a1d07dd6d5f38aace66ff0a19c4575c834a6fdb0f8a226c01 libgcrypt-1.4.5-11.el6_4.x86_64.rpm
d97f0c12e08acb0844404a6ba4ab288d20dcf2a16d03bcf5647b05eba3e98f65 libgcrypt-devel-1.4.5-11.el6_4.i686.rpm
472773662216defd7ac43f73dac325fca2402009ffdf11d81efc6fe16b86c4c3 libgcrypt-devel-1.4.5-11.el6_4.x86_64.rpm

Source:
c963b5bf4c84d5798d987e86b4e600ce3c7ae03e035096d88982385a81dcdbbc libgcrypt-1.4.5-11.el6_4.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CentOS Dojo at Madrid, Spain - Nov 8th 2013

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

Our next Dojo is going to be taking place at Madrid on the 8th Nov
2013. Details on the venue and registration are on the wiki page at
http://wiki.centos.org/Events/Dojo/Madrid2013

As has now become tradition, the Dojo will start at 9:30am and will
run through to just after 5pm localtime. At which point some of us
will decamp to a watering hole for drinks.

On the day we have:

Jaime Melis talking about KVM and Clouds built on KVM (with OpenNebula)

Luis Fernando Muñoz Mejías is doing two talks, based on his experience
at the Gent University. The first one is on and around yum used across
large number of machines, their lessons learnt and challenges
encountered. His second talk is about Quattor and Aquilon, tools that
help with life cycle management - with some very interesting features
like policy based config state.

Lorenzo Martínez Rodríguez is going to be talking about begining steps
on CentOS security and how one might secure a CentOS machine for some
typical roles, and briefly touching on topics like audit, logs and
forensics.

Xavier Gonzalez is going to be showing off Viapps, a tool they have
been working on to manage CentOS servers for typical services and
tasks but treating the server as an appliance.

And I will be doing a talk on the CentOS Project, the road ahead - the
big things that we are working on and the plans for the next 6 to 8
months.

We will also have an open space session, anyone is welcome to come up
and talk about something they care about, or anything they have a
problem with and are looking for advice - even if there are things
that the CentOS project and CentOS Linux might be able to do better;
or show off some tools or project they have been working on that is
related to CentOS or runs on CentOS.

URL's of note:

Register at: https://centosdojomadrid2013.eventbrite.co.uk/
Event page: http://wiki.centos.org/Events/Dojo/Madrid2013

Venue:
Parque Científico de Madrid
Campus de Cantoblanco
C/ Faraday, 7
28049 – Madrid, Spain

Look forward to seeing some of you guys there.


- --
Karanbir Singh, Project Lead, The CentOS Project
+44-207-0999389 | http://www.centos.org/ | twitter.com/CentOS
GnuPG Key : http://www.karan.org/publickey.asc
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iEYEARECAAYFAlJpLHMACgkQMA29nj4Tz1v3JwCfY0kqhEp/VpdVKJbkd2b6viZI
BVIAni4DwMEeYzvdS3titjRoiP6ymw0L
=DmtM
-----END PGP SIGNATURE-----
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce

Wednesday, October 23, 2013

[USN-2005-1] Cinder vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSaDWdAAoJEFHb3FjMVZVzsBoQAIkhh7kVtdynWseLbdQsp8SK
rqzma/a2iJRxe/hIX2UnbGzenf4iUEHzhuKHR3EOnR3nTc1ta3DfMcTTad9jS2GR
zDrenXc4ab/gibwUCcCcU6sMX40oQMFtQYV9JDOfieQevSmYEDgUopOUnqNu0CnQ
+GFXk+FIwffn0EneImkh2mlxJu5qDSMJAeR9GPhOy3J2ZCIzsbApxDt3uz+nW4ip
+x/5FgumMho1O+u2CSNX7RNEOKJ7zJhLmjll1sSd+yWX2uWVxzkgVxJNuiHHiUMc
8tlsemWy9sLIW6xPGEoXXy7DLPF7EbF2s8S/TQx0ia78K9EStPj1sYcu741xDBSn
U6YrA0CYpzVd5P09Z5IJys2/OoiPawu8E6ad0cLzVBdnMS1W6xgAR3xyq6BEmvtp
V3Wa3VYiE3gXwyl+uPAcS2tlTl553EJ1DzoLX8Wyzt6jrQ0CTH9fgH+kHik+tBaM
XUmfmeLIkkf0xhgRlDQU0s08feRLpzWduWc8WjmA2rVkRpLEED949iuGp+D/ZIub
7hkUuS8T2Yz3THR383hJ0pYG9fFaS6IH5tz3auBwfsjtkcCUiuJjcbXIIo6vC72G
VA70YrPWJhYZoWt9ndLIIBEsOGOUQVGKdNYOIpkpqodRL/IjoyrA87pbSQz2zqqP
Kz2OyT4RQfPNt+MvDU3H
=gxjI
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2005-1
October 23, 2013

cinder vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04

Summary:

Cinder could be made to crash or expose sensitive information.

Software Description:
- cinder: OpenStack storage service

Details:

Rongze Zhu discovered that the Cinder LVM driver did not zero out data
when deleting snapshots. This could expose sensitive information to
authenticated users when subsequent servers use the volume. (CVE-2013-4183)

Grant Murphy discovered that Cinder would allow XML entity processing. A
remote unauthenticated attacker could exploit this using the Cinder API to
cause a denial of service via resource exhaustion. (CVE-2013-4179,
CVE-2013-4202)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
python-cinder 1:2013.1.3-0ubuntu2.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2005-1
CVE-2013-4179, CVE-2013-4183, CVE-2013-4202

Package Information:
https://launchpad.net/ubuntu/+source/cinder/1:2013.1.3-0ubuntu2.1

[USN-2003-1] Glance vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSaDVnAAoJEFHb3FjMVZVzZo0P/2sdHFAHTJ4/rWJJjnqUyQED
O1prqa8pJPvJvXEEyD5xf40Q6jwRY7DVEfWHkYMIt+bbazZi2k+/n6+r2W7h95Rf
Dsj7Ud/DRKiaMqlFGdSbu9pykSZzr7d9q2HudCEhzKLv2SjD+MT0KvszWBGvbNg/
OMdzTznqdNC/0u+ZnVfNWAQ+y3Y80dwjsnRFsNAPAr6GBWXGTxy2YUXaTpjuBA7X
48Ir1ii8ica4H4p0oOfQu3voxRTLMQ2I5gb5Ir76fmCzKhS6kjJvsle2HzD1msq0
/qQfkI5lsxljKuIxUfn/C9/pX2KDqydpWxITgKI33HMWuRhpyKIz10xdcbFo4c+s
UAQGNtezJXkeFtercYUuLTPlhvxhgV904/ABg16MJ4i1rsV5zWu4z7+vZoMe/wTp
m7aLbMxxXd/tq8KxTrP1RGx/9naJ39qyneNA4NJhHZH8AQ9xnAelJmqlT8jtcnel
EYHyUbCDKmqljYheCDgE6QYIEcuntTQLAgyfJq8/pI/DyIDzyueQtpJkL8mhQ/Sw
9GyFt89EF0Kp2XP3cp2QKUXPt+be63SNfiRoXoJvCbYv5D0YRacGo7LyOzA07Q+O
Y9CCdbAsW4l35KA+1f+auzoGO7J/if8gFKHX4mx+eErQTBiZ3Z5eovW0tv4Swiay
4nlKeaVSaEXgguwMvOMU
=XrUz
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2003-1
October 23, 2013

glance vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04
- Ubuntu 12.10

Summary:

Glance could be made to expose sensitive information over the network
under certain circumstances.

Software Description:
- glance: OpenStack Image Registry and Delivery Service

Details:

Stuart McLaren discovered that Glance did not properly enforce the
'download_image' policy for cached images. An authenticated user could
exploit this to obtain sensitive information in an image protected by this
setting.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
python-glance 1:2013.1.3-0ubuntu1.1

Ubuntu 12.10:
python-glance 2012.2.4-0ubuntu1.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2003-1
CVE-2013-4428

Package Information:
https://launchpad.net/ubuntu/+source/glance/1:2013.1.3-0ubuntu1.1
https://launchpad.net/ubuntu/+source/glance/2012.2.4-0ubuntu1.1

[USN-2004-1] python-glanceclient vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSaDWEAAoJEFHb3FjMVZVz7e4QALPEuoEvAxgrEYmgsM8YF1xS
drOHPC1R/W74cFmBmq/yRfO24AJkJliBeQTwEOuOpxvwP0ONo417lSiyTCDmqnwR
xs2vhgcuALKJXmwkO+aA+88BG4K+/dFz5Ix9Pmk+lix3lycL3WUa9YfX5cAlh5zQ
9JAYbXUTRhxlMDhWtYD2+r62oxWc6QW+/GEqwz8ZLk+x8daXzSTji6dPlhF3cd8Y
TlU3fHn9hitEapzs4AuqkuI+hYjYMeVbul5JmvDzGDkN5xYZZT6eV8R/GrzT9GcH
yKac3gqvDWkMba1SeeEO47sp6W/dSe/qCpxlGwJJKirMCkHUd1o2lkE36t01Y5fI
Jp5UTr/ymF1afhD5Jnp3KQPPEsVojusAmkIvc2KbkLLdMBTMTYGbucaxXk/uwGYT
0EHwYY2WedopBoQNhRdTIrlT5l+kRnxPACokMTFVvw2SN/eMgoVSfTkir7PbxkbK
MXjKpdl4OuoD9gtUGG0egA8Jp8Hid/ab8WIqF2dT2IAsrZWTlc9YbpBezjesxmfH
aUdzayDaDikmumZXG7qsMtBhJnEdaHfFRHvTbRcQ8Flf07788eJrJrO/vY2CDRTb
JapdgigELSuhW4W5QaBRoEgHOvHZWjqy/CJlq+6S4j4aVCzSQdUrfds0Tnj6tPKF
q5LzpMgFPoFGlGldZ66k
=UZC2
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2004-1
October 23, 2013

python-glanceclient vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04

Summary:

python-glanceclient could be made to expose sensitive information over the
network.

Software Description:
- python-glanceclient: Client library for Openstack glance server.

Details:

Thomas Leaman discovered that the Python client library for Glance did not
properly verify SSL certificates. A remote attacker could exploit this to
perform a man in the middle attack.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
python-glanceclient 1:0.9.0-0ubuntu1.2

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2004-1
CVE-2013-4111

Package Information:
https://launchpad.net/ubuntu/+source/python-glanceclient/1:0.9.0-0ubuntu1.2

[USN-2002-1] Keystone vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSaDU/AAoJEFHb3FjMVZVzbOkQAI4cazKdDv0SOl4lgRytkY3A
ioDIzSCBDgH+iY1PhVIhQjgDUKmZ0Uexj70AgmZcUz0Zfrx6hpzYuNQ2z6FxGh+t
BLtsYF19pGyTHy20zdbqPvweW9OolXuDKGrksEixSDdRhXCOlkvsciFhIi41sViE
VpAzIy2i1YUtYaJt3dIfQEszngYb5vI230Q/cqhnl94niWGwa7zigR4xBDMEO8vR
YX0t79BQ2QKcDfj2JNCznQwwIMFqi6SrgE7za0Gi546xghvXtYpi+toP7S+0t+xA
S0C5Mn2O7ApOp8AlTj7bc9ujw6atmt3eJJShifXcaIdf2GvjA8r+FDlJjndw6O4Q
fpEpzwiIQn+Ev8dItbZCz4jIiAc92qnxi6pRIz3WlbcZA0zeafv2cm9LRRVOpEkL
Jl/x3q2MW+edZElLCIwpmobXi+4r/tWsC2i21dLklkRmLD3L7ebbuX/sNFHwZM9J
VUr1CJLuUYVRy7xZDx3mzqzUgBcEmEYO/hjDqCpydshqa1GyTI2jG5Ts2xxpYgw3
KBQF1F8NSV56fkNBZ5sBRFSBymsiKDQ6Q1caLrY8EUhltpZfk/4ulOmoKJP4lTJf
kers4NPG+7zWVKeq/Oh6Naf8xtJASZK8DgjeOo6nXz1iUwpvT2HzXK/xtsyPC1f4
/bZUdrp4EnWf08sq0zbG
=121x
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2002-1
October 23, 2013

keystone vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04
- Ubuntu 12.10

Summary:

Keystone would improperly grant access to invalid tokens under certain
circumstances.

Software Description:
- keystone: OpenStack identity service

Details:

Chmouel Boudjnah discovered that Keystone did not properly invalidate user
tokens when a tenant was disabled which allowed an authenticated user to
retain access via the token. (CVE-2013-4222)

Kieran Spear discovered that Keystone did not properly verify PKI tokens
when performing revocation when using the memcache and KVS backends. An
authenticated attacker could exploit this to bypass intended access
restrictions. (CVE-2013-4294)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
python-keystone 1:2013.1.3-0ubuntu1.1

Ubuntu 12.10:
python-keystone 2012.2.4-0ubuntu3.2

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2002-1
CVE-2013-4222, CVE-2013-4294

Package Information:
https://launchpad.net/ubuntu/+source/keystone/1:2013.1.3-0ubuntu1.1
https://launchpad.net/ubuntu/+source/keystone/2012.2.4-0ubuntu3.2