Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <5050C83C.1010400@redhat.com>
Date: Wed, 12 Sep 2012 13:37:00 -0400
From: Russell Bryant <rbryant@...hat.com>
To: Matt Joyce <matt@...resistor.com>
CC: Thierry Carrez <thierry@...nstack.org>, oss-security@...ts.openwall.com,
        openstack@...ts.launchpad.net,
        "(openstack@...ts.launchpad.net)" <openstack@...ts.launchpad.net>
Subject: Re: [Openstack] [Openstack-announce] [OSSA 2012-014] Revoking a role
 does not affect existing tokens (CVE-2012-4413)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 09/12/2012 01:07 PM, Matt Joyce wrote:
> This is not a repeat of cve-2012-3426?

It's related, but not the same.  That CVE did not include this
specific issue (existing tokens including roles that may have since
been revoked).  It was for some other problems around token
expiration, though.

For reference: https://lists.launchpad.net/openstack/msg15164.html

- -- 
Russell Bryant
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://www.enigmail.net/

iEYEARECAAYFAlBQyDwACgkQFg9ft4s9SAYVGgCfcQuY/uk4HlXh9ToPqqSPl7Nf
h6kAoK/ZUqvTeHSkPbWyi1Y8+PEkt4tD
=Cz/+
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.