Bug 852784 (CVE-2013-6396) - VUL-2: CVE-2013-6396: python-swiftclient: SSL certificate verification security issue
Summary: VUL-2: CVE-2013-6396: python-swiftclient: SSL certificate verification securi...
Status: RESOLVED FIXED
Alias: CVE-2013-6396
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2013-12-12
Assignee: Jiří Suchomel
QA Contact: Security Team bot
URL:
Whiteboard: CVSSv2:NVD:CVE-2013-6396:5.8:(AV:N/AC...
Keywords:
Depends on:
Blocks:
 
Reported: 2013-11-28 09:47 UTC by Victor Pereira
Modified: 2016-10-20 10:23 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2013-11-28 09:47:01 UTC
CVE-2013-6396

Python-swiftclient fails to properly verify the server SSL certificates, which can be exploited by malicious people to conduct spoofing attacks via MitM (Man in the Middle attacks) and possibly leading to disclosure of sensitive information.


References:
https://bugs.gentoo.org/show_bug.cgi?id=491368
https://bugs.launchpad.net/python-swiftclient/+bug/1199783
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-6396
https://bugzilla.redhat.com/show_bug.cgi?id=1031652
Comment 1 Swamp Workflow Management 2013-11-28 09:48:34 UTC
The SWAMPID for this issue is 55265.
This issue was rated as moderate.
Please submit fixed packages until 2013-12-12.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 2 Swamp Workflow Management 2013-11-28 23:00:17 UTC
bugbot adjusting priority
Comment 10 Sebastian Krahmer 2014-01-08 15:36:23 UTC
Ok, sounds something for a VUL-2 tag. I hope its tracked somewhere
in the Cloud 3 roadmap then so this issue is not forgotten about.
Comment 15 Victor Pereira 2014-12-16 09:15:18 UTC
hi any news related with this issue? is that already fixed?
Comment 18 Johannes Segitz 2015-04-08 13:32:24 UTC
fixed in current versions of cloud