UbuntuUpdates.org

Package "python-keystoneclient"

Name: python-keystoneclient

Description:

Client library for OpenStack Identity API

Latest version: 1:0.7.1-ubuntu1.2
Release: trusty (14.04)
Level: security
Repository: main

Links


Download "python-keystoneclient"


Other versions of "python-keystoneclient" in Trusty

Repository Area Version
base main 1:0.7.1-ubuntu1
updates main 1:0.7.1-ubuntu1.3

Changelog

Version: 1:0.7.1-ubuntu1.2 2015-08-06 03:06:43 UTC

  python-keystoneclient (1:0.7.1-ubuntu1.2) trusty-security; urgency=medium

  * SECURITY UPDATE: incorrect cert verification with ssl_insecure option
    - debian/patches/CVE-2014-7144.patch: properly parse option in
      keystoneclient/middleware/auth_token.py.
    - CVE-2014-7144
  * SECURITY UPDATE: incorrect cert verification with ssl_insecure option
    - debian/patches/CVE-2015-1852.patch: properly parse option in
      keystoneclient/middleware/s3_token.py, added test to
      keystoneclient/tests/test_s3_token_middleware.py.
    - CVE-2015-1852
  * Properly run test suite during build:
    - debian/control: added python-testresources to Build-Depends
    - debian/rules: call testr directly

 -- Marc Deslauriers Thu, 16 Jul 2015 15:05:21 -0400

CVE-2014-7144 OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "in
CVE-2015-1852 The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when



About   -   Send Feedback to @ubuntu_updates