Bug#700240: Vulnerability in OpenStack Keystone

2013-02-14 Thread Thierry Carrez
Thomas Goirand wrote: > Hi Thierry and Dan, > > I got very confused about CVE-2013-0247 and CVE-2013-0270. > > I have already uploaded the fix for CVE-2013-0247 in Debian SID, and now > I'm trying to understand what CVE-2013-0270 is about. My request about > it in the Openstack development list w

Bug#700240: Vulnerability in OpenStack Keystone

2013-02-13 Thread Thomas Goirand
On 01/30/2013 11:33 PM, Thierry Carrez wrote: > This is an advance warning of a vulnerability discovered in OpenStack, > to give you, as downstream stakeholders, a chance to coordinate the > release of fixes and reduce the vulnerability window. Please treat the > following information as confidenti