Bug 892097 (CVE-2014-5251) - VUL-0: CVE-2014-5251: openstack-keystone: revocation events are broken with mysql
Summary: VUL-0: CVE-2014-5251: openstack-keystone: revocation events are broken with m...
Status: RESOLVED FIXED
Alias: CVE-2014-5251
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Bernhard Wiedemann
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/105060/
Whiteboard: maint:released:sle11-sp3-cl4:58666
Keywords:
Depends on:
Blocks:
 
Reported: 2014-08-15 12:56 UTC by Johannes Segitz
Modified: 2014-09-26 23:48 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2014-08-15 12:56:13 UTC
mysql only stores timestamps with an accuracy of seconds rather than microseconds, doing comparisons of token expiration times will fail and tokens will not show up as being revoked.

Upstream fix:
https://git.openstack.org/cgit/openstack/keystone/commit/?id=7aee6304f653475a4130dc3e5be602e91481f108

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1127259
https://bugs.launchpad.net/keystone/+bug/1347961
http://seclists.org/oss-sec/2014/q3/296
Comment 1 Swamp Workflow Management 2014-08-15 22:00:30 UTC
bugbot adjusting priority
Comment 2 Alexander Bergmann 2014-08-18 10:25:12 UTC
CVE-2014-5251 was assigned to this issue.
Comment 3 Vincent Untz 2014-08-19 07:34:58 UTC
Note that this seems to be a mysql-specific issue (although I'm not sure that people checked postgresql is not affected); so we might not be affected.
Comment 4 Bernhard Wiedemann 2014-08-19 08:05:43 UTC
I checked
http://www.postgresql.org/docs/9.1/static/datatype-datetime.html
and it says, timestamp resolution  	1 microsecond / 14 digits

so SUSE Cloud is not affected.
Only openSUSE could use updates.
Icehouse already got a backport
and the patch does not apply to Havana.
Comment 5 Bernhard Wiedemann 2014-08-19 08:15:02 UTC
Actually, there is no Icehouse in openSUSE either
and our OBS project already has the fix.
Comment 7 Swamp Workflow Management 2014-09-26 19:04:34 UTC
SUSE-SU-2014:1219-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 892095,892097,892099
CVE References: CVE-2014-5251,CVE-2014-5252,CVE-2014-5253
Sources used:
SUSE Cloud 4 (src):    openstack-keystone-2014.1.3.dev3.gb812131-0.7.1, openstack-keystone-doc-2014.1.3.dev3.gb812131-0.7.1