Bug 858459 (CVE-2014-0006) - VUL-0: CVE-2014-0006: openstack-swift: timing attack vulnerability
Summary: VUL-0: CVE-2014-0006: openstack-swift: timing attack vulnerability
Status: RESOLVED FIXED
Alias: CVE-2014-0006
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2014-03-06
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:released:sle11-sp3-uptu:56445 m...
Keywords:
Depends on:
Blocks:
 
Reported: 2014-01-13 08:31 UTC by Sebastian Krahmer
Modified: 2014-05-07 11:32 UTC (History)
4 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 8 Swamp Workflow Management 2014-02-20 15:23:46 UTC
The SWAMPID for this issue is 56353.
This issue was rated as moderate.
Please submit fixed packages until 2014-03-06.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 9 Marcus Meissner 2014-02-24 16:37:18 UTC
is public

http://www.openwall.com/lists/oss-security/2014/01/17/5

OpenStack Security Advisory: 2014-002
CVE: CVE-2014-0006
Date: January 16, 2013
Title: Swift TempURL timing attack
Reporter: Samuel Merritt (SwiftStack)
Products: Swift
Affects: All supported versions

Description:
Samuel Merritt from SwiftStack reported a timing attack vulnerability in
Swift TempURL middleware. By analyzing response times to arbitrary
TempURL requests, an attacker may be able to guess valid secret URLs and
get access to objects that were only intended to be publicly shared with
specific recipients. In order to use this attack, the attacker needs to
know the targeted object name, and the object account needs to have a
TempURL key set. Only Swift setups enabling the TempURL middleware are
affected.

Icehouse (development branch) fix:
https://review.openstack.org/#/c/67185/

Havana (1.10.0) fix:
https://review.openstack.org/#/c/67186/

Grizzly (1.8.0) fix:
https://review.openstack.org/#/c/67187/

Note: the Icehouse fix will be included in upcoming 1.12.0 release.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0006
https://bugs.launchpad.net/swift/+bug/1265665

Regards,

-- 
Thierry Carrez
OpenStack Vulnerability Management Team
Comment 10 Vincent Untz 2014-02-26 10:42:46 UTC
Jiri: can you make sure that the fixes are in OBS (in C:O:G:S and C:O:H:S). We simply copy our packages from there, so if you don't commit the fixes there, they will be lost later on.
Comment 11 Jiří Suchomel 2014-02-26 11:46:42 UTC
https://build.opensuse.org/request/show/223946 for Havana
https://build.suse.de/request/show/33214 for  Devel:Cloud:3:Staging


Our Grizzly sources (C:O:G:S) have already the patch applied.
Comment 12 Marcus Meissner 2014-02-26 12:43:07 UTC
Hmm.

Something went wrong.

We have openstack-swift 1.8.0.1+git.1375920359.1f4ec23 now, in
both CLOUD 2.0 and 3.0 update channels.

need to clarify with maint-coord and vincent.
Comment 16 Bernhard Wiedemann 2014-03-07 15:00:21 UTC
This is an autogenerated message for OBS integration:
This bug (858459) was mentioned in
https://build.opensuse.org/request/show/225068 Factory / openstack-swift
Comment 17 Swamp Workflow Management 2014-04-17 13:45:39 UTC
Update released for: openstack-swift, openstack-swift-account, openstack-swift-container, openstack-swift-doc, openstack-swift-object, openstack-swift-proxy, openstack-swift-test, python-swift
Products:
SUSE-CLOUD 3.0 (x86_64)
Comment 18 Swamp Workflow Management 2014-04-17 17:05:04 UTC
SUSE-SU-2014:0547-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 858459
CVE References: CVE-2014-0006
Sources used:
SUSE Cloud 3 (src):    openstack-swift-1.10.0-0.13.2, openstack-swift-doc-1.10.0+git.1382343573.79e2a50-0.13.3
Comment 20 Swamp Workflow Management 2014-05-07 07:45:54 UTC
Update released for: openstack-swift, openstack-swift-account, openstack-swift-container, openstack-swift-doc, openstack-swift-object, openstack-swift-proxy, openstack-swift-test, python-swift
Products:
SUSE-CLOUD 2.0 (x86_64)
Comment 21 Swamp Workflow Management 2014-05-07 11:04:25 UTC
SUSE-SU-2014:0547-2: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 858459
CVE References: CVE-2014-0006
Sources used:
SUSE Cloud 2.0 (src):    openstack-swift-1.8.0.1+git.1375920359.1f4ec23-0.9.1, openstack-swift-doc-1.8.0.1+git.1375920359.1f4ec23-0.9.1