Security update for openstack-swift
SUSE Security Update: Security update for openstack-swift
The openstack SWIFT component has been updated to fix a
security issue:
* CVE-2012-4406: The pickle serialization for memcache
could be exploited to execute code. It was replaced by JSON.
Security Issue reference:
* CVE-2012-4413
>
Announcement ID: | SUSE-SU-2012:1352-1 |
Rating: | moderate |
References: | #779215 |
Affected Products: |
An update that fixes one vulnerability is now available.
Description:
The openstack SWIFT component has been updated to fix a
security issue:
* CVE-2012-4406: The pickle serialization for memcache
could be exploited to execute code. It was replaced by JSON.
Security Issue reference:
* CVE-2012-4413
Patch Instructions:
To install this SUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- SUSE Cloud 1.0:
zypper in -t patch sleclo10sp2-openstack-swift-6819
To bring your system up-to-date, use "zypper patch".
Package List:
- SUSE Cloud 1.0 (x86_64):
- openstack-swift-1.4.8+git.1332408124.4a6fead-0.11.1
- openstack-swift-account-1.4.8+git.1332408124.4a6fead-0.11.1
- openstack-swift-container-1.4.8+git.1332408124.4a6fead-0.11.1
- openstack-swift-doc-1.4.8+git.1332408124.4a6fead-0.11.1
- openstack-swift-object-1.4.8+git.1332408124.4a6fead-0.11.1
- openstack-swift-proxy-1.4.8+git.1332408124.4a6fead-0.11.1
- python-swift-1.4.8+git.1332408124.4a6fead-0.11.1
References:
- http://support.novell.com/security/cve/CVE-2012-4413.html
- https://bugzilla.novell.com/779215
- http://download.suse.com/patch/finder/?keywords=9d6ca417db66a8fd03dcda14001eaa95