Bug 861481 (CVE-2014-0040) - VUL-1: CVE-2014-0040: openstack-heat-templates: use of HTTP to download signing keys/code
Summary: VUL-1: CVE-2014-0040: openstack-heat-templates: use of HTTP to download signi...
Status: RESOLVED WONTFIX
: CVE-2014-0041 CVE-2014-0042 (view as bug list)
Alias: CVE-2014-0040
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-01-31 10:08 UTC by Alexander Bergmann
Modified: 2016-04-27 19:28 UTC (History)
4 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2014-01-31 10:08:06 UTC
Grant Murphy found several problems within the openstack/heat-templates project.

* yum repositories that make connections via http (should be https)

CVE-2014-0040 was assigned to this issue.

External reference:
https://bugs.launchpad.net/heat-templates/+bug/1267635
https://github.com/openstack/heat-templates/
https://bugzilla.redhat.com/show_bug.cgi?id=1059514
Comment 1 Swamp Workflow Management 2014-01-31 23:00:22 UTC
bugbot adjusting priority
Comment 2 Dirk Mueller 2014-04-22 08:37:43 UTC
Added to C:O:H:S
Comment 3 Dirk Mueller 2014-04-22 08:38:04 UTC
*** Bug 861482 has been marked as a duplicate of this bug. ***
Comment 4 Dirk Mueller 2014-04-22 08:38:13 UTC
*** Bug 861483 has been marked as a duplicate of this bug. ***
Comment 6 Marcus Meissner 2014-09-25 15:57:34 UTC
did we release a fix for htis for cloud 3?
Comment 7 Dirk Mueller 2014-09-29 08:04:50 UTC
I don't know. if we did, there should be the following reference in the changes file: 

  + Secure private repo files added to environment (bnc#861481,
  CVE-2014-0040, bnc#861482, CVE-2014-0041, bnc#861483, CVE-2014-0042)
Comment 8 Victor Pereira 2015-02-13 11:37:07 UTC
since we dont update cloud 3 anymore, and it is in cloud 4 and cloud, i will close it.