Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 511000 (CVE-2014-0204) - <sys-auth/keystone-2014.1-r2: user and group id mismatch (CVE-2014-0204) (OSSA 2014-015)
Summary: <sys-auth/keystone-2014.1-r2: user and group id mismatch (CVE-2014-0204) (OSS...
Status: RESOLVED FIXED
Alias: CVE-2014-0204
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-05-22 07:22 UTC by Agostino Sarubbo
Modified: 2014-06-04 08:17 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-05-22 07:22:22 UTC
From ${URL} :

OpenStack Security Advisory: 2014-015
CVE: CVE-2014-0204
Date: May 21, 2014
Title: Keystone user and group id mismatch
Reporter: Michael Stancampiano (IBM)
Products: Keystone
Versions: 2014.1

Description:
Michael Stancampiano from IBM reported a vulnerability in Keystone.
Someone with write access to the user and group repository (such as the
LDAP directory server) may willingly or unwillingly grant additional
rights by picking the same IDs for users and groups, resulting in roles
assigned to a group being assigned to the affected user even if he is
not a member of this group. Only Keystone setups using LDAP for the
Identity driver are affected.

Juno (development branch) fixes:
https://review.openstack.org/94396
https://review.openstack.org/94470

Icehouse fix:
https://review.openstack.org/94397

Notes:
This fix will be included in the juno-1 development milestone and in
a future 2014.1.1 release.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0204
https://launchpad.net/bugs/1309228


@maintainer(s): since the package or the affected version has never been marked as stable, we don't need to stabilize it. After the bump, please remove the affected versions from the tree.
Comment 1 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2014-05-23 18:25:21 UTC
Still waiting on an actual patchset to be committed :|

https://review.openstack.org/#/c/94397/
Comment 2 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2014-06-01 02:19:33 UTC
fixed in keystone-2014.1-r2
Comment 3 Agostino Sarubbo gentoo-dev 2014-06-04 08:17:33 UTC
Closing as noglsa