Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.841479
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-1875-1)
Summary:The remote host is missing an update for the 'keystone' package(s) announced via the USN-1875-1 advisory.
Description:Summary:
The remote host is missing an update for the 'keystone' package(s) announced via the USN-1875-1 advisory.

Vulnerability Insight:
Eoghan Glynn and Alex Meade discovered that Keystone did not properly
perform expiry checks for the PKI tokens used in Keystone. If Keystone were
setup to use PKI tokens, a previously authenticated user could continue to
use a PKI token for longer than intended. This issue only affected Ubuntu
12.10 which does not use PKI tokens by default. (CVE-2013-2104)

Jose Castro Leon discovered that Keystone did not properly authenticate
users when using the LDAP backend. An attacker could obtain valid tokens
and impersonate other users by supplying an empty password. By default,
Ubuntu does not use the LDAP backend. (CVE-2013-2157)

Affected Software/OS:
'keystone' package(s) on Ubuntu 12.10, Ubuntu 13.04.

Solution:
Please install the updated package(s).

CVSS Score:
5.5

CVSS Vector:
AV:N/AC:L/Au:S/C:N/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-2104
RHSA-2013:0944
http://rhn.redhat.com/errata/RHSA-2013-0944.html
USN-1851-1
http://www.ubuntu.com/usn/USN-1851-1
USN-1875-1
http://www.ubuntu.com/usn/USN-1875-1
[oss-security] 20130528 [OSSA 2013-014] Missing expiration check in Keystone PKI tokens validation (CVE-2013-2104)
http://www.openwall.com/lists/oss-security/2013/05/28/7
https://bugs.launchpad.net/python-keystoneclient/+bug/1179615
openSUSE-SU-2013:1089
http://lists.opensuse.org/opensuse-updates/2013-06/msg00198.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-2157
60545
http://www.securityfocus.com/bid/60545
RHSA-2013:0994
http://rhn.redhat.com/errata/RHSA-2013-0994.html
RHSA-2013:1083
http://rhn.redhat.com/errata/RHSA-2013-1083.html
[oss-security] 20130613 [OSSA 2013-015] Authentication bypass when using LDAP backend (CVE-2013-2157)
http://www.openwall.com/lists/oss-security/2013/06/13/3
CopyrightCopyright (C) 2013 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.