• [SECURITY] [DSA 3953-1] aodh security update

    From Luciano Bello@1:229/2 to All on Wed Aug 23 22:10:01 2017
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA256

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3953-1 [email protected] https://www.debian.org/security/ Luciano Bello August 23, 2017 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : aodh
    CVE ID : CVE-2017-12440
    Debian Bug : 872605

    Zane Bitter from Red Hat discovered a vulnerability in Aodh, the alarm
    engine for OpenStack. Aodh does not verify that the user creating the
    alarm is the trustor or has the same rights as the trustor, nor that the
    trust is for the same project as the alarm. The bug allows that an authenticated users without a Keystone token with knowledge of trust IDs
    to perform unspecified authenticated actions by adding alarm actions.

    For the stable distribution (stretch), this problem has been fixed in
    version 3.0.0-4+deb9u1.

    We recommend that you upgrade your aodh packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCAAdFiEEayzFlnvRveqeWJspbsLe9o/+N3QFAlmd3fYACgkQbsLe9o/+ N3Se8xAAimg7Xo4NfIIGKBctTpzCv5cmxC49w4NqeC37a2uaLPOA3DLU/WV30S13 st+NelwaFHrhE/hXgiWgoGi1p2b2v4Gs/C//NO70qNoXIRePs76+ic7RWAAB9ddI J7n1CiTUtNisILP6EmhEoOd6kSReCc34jUc7s2YPr0DS0ziEcOJrR8X2SfK621zs nfxPGMUMBE5+Fk9gOrXz1zCJguGvIQBRnSNQjLf8eFZvva0e2nAulIvq6buvKW2B 9ZftuNHQnpW3/k+1kDZ7FqMTvFsC5gQdEF9c+qmZd54lyb5qWgds9W2Xh3meQZDM oq64lGSozMcFIfeLLFfCktQfpmxInIHsjT+DK8FnAr3UgGD6zhCJMTNIxP6p+3xB 2Y2z+PUFMumpWNOtb3o/9DEauL1v5BxCTRLr7C0sr0MLdypm6JmH+ASv5FaKN8o4 i9mgabqext57ejKVqOhDGTcZJJB3uN6N8WeOTt/E3bU22kSN9H8BeBX9RHsgVnsF wehYkH1qEynb+E6dA6o0epMX/Of926PTeUsu+3ipPZWALM/dSvjkwdr+LRjDt8w4 sd5k//1SH9SnUQTiPDrEk2hu/HEj01HGrhh8eJNn9+2Zq7+ZmFUgiPduyFWlEoBk Ky5zI5NtuTvgW1OjH+GX1tZNc8EPzPDlapB1I+RvCUITQWVtDlQ=
    =OTsW
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)