Bug 887577 (CVE-2014-3429) - VUL-0: IPython: CVE-2014-3429: ipython: cross-domain websocket hijacking vulnerability
Summary: VUL-0: IPython: CVE-2014-3429: ipython: cross-domain websocket hijacking vuln...
Status: RESOLVED FIXED
Alias: CVE-2014-3429
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/103641/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-07-16 14:43 UTC by Victor Pereira
Modified: 2016-04-27 19:30 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2014-07-16 14:43:06 UTC
CVE-2014-3429

It was reported  that IPython's Notebook server suffered from a flaw where it did not verify the origin of websocket requests.  An attacker with knowledge of the IPython kernel ID could run arbitrary code on a user's machine with the privileges of the user running the IPython Notebook server, if the client visited a crafted malicious page.  This was corrected upstream in the 2.0.0 release. 



References:
http://openwall.com/lists/oss-security/2014/07/15/2
https://github.com/ipython/ipython/pull/4845
http://lambdaops.com/cross-origin-websocket-hijacking-of-ipython
https://bugzilla.redhat.com/show_bug.cgi?id=1119890
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3429
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3429
Comment 1 Swamp Workflow Management 2014-07-16 22:00:26 UTC
bugbot adjusting priority
Comment 2 SMASH SMASH 2014-07-29 08:35:16 UTC
Affected packages:

SLE-11-SP3: IPython
Comment 3 Jan Matejek 2014-08-11 17:48:14 UTC
SLE11 is in fact not affected, because its IPython 0.8.4 does not have the Notebook feature.

SLE12 is fixed in SR 42488

openSUSE 12.3 and 13.1 are affected, Factory has a fixed version already
Comment 5 Jan Matejek 2014-08-11 18:25:08 UTC
12.3 and 13.1 fixed, handing over to security
Comment 6 Bernhard Wiedemann 2014-08-11 19:00:24 UTC
This is an autogenerated message for OBS integration:
This bug (887577) was mentioned in
https://build.opensuse.org/request/show/244254 12.3 / IPython
https://build.opensuse.org/request/show/244257 13.1 / IPython
Comment 7 Swamp Workflow Management 2014-08-23 00:05:29 UTC
openSUSE-SU-2014:1060-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 887577
CVE References: CVE-2014-3429
Sources used:
openSUSE 13.1 (src):    IPython-0.13.1-4.4.1, IPython-1.0.0-2.4.3, python-pyzmq-13.0.0-4.4.1
openSUSE 12.3 (src):    IPython-0.13.1-4.4.1, python3-IPython-0.13.1-4.4.1
Comment 8 Marcus Meissner 2014-09-01 13:59:08 UTC
was released