Bug#700240: keystone: CVE-2013-0270: Large HTTP request DoS

2013-02-13 Thread Salvatore Bonaccorso
Hi Thomas On Thu, Feb 14, 2013 at 12:55:02PM +0800, Thomas Goirand wrote: > On 02/14/2013 05:36 AM, Salvatore Bonaccorso wrote: > > Hi Thomas > > > > Cc'in the Security Team as they might give better input on this. > > > > I have done this as best to my knowledge. I was reporting > > found/assig

Bug#700240: keystone: CVE-2013-0270: Large HTTP request DoS

2013-02-13 Thread Thomas Goirand
On 02/14/2013 05:36 AM, Salvatore Bonaccorso wrote: > Hi Thomas > > Cc'in the Security Team as they might give better input on this. > > I have done this as best to my knowledge. I was reporting > found/assigned CVE's, but mistakes can happen. E.g. in keystone > changelog it's refering to CVE-201

Bug#700240: keystone: CVE-2013-0270: Large HTTP request DoS

2013-02-13 Thread Salvatore Bonaccorso
Hi Thomas Cc'in the Security Team as they might give better input on this. On Wed, Feb 13, 2013 at 10:14:20PM +0800, Thomas Goirand wrote: > Hi Salvatore, > > This was already fixed before you submitted the bug. See #699835. > > Next time, please check the bug history, because this made me loos

Bug#700240: keystone: CVE-2013-0270: Large HTTP request DoS

2013-02-10 Thread Salvatore Bonaccorso
Package: keystone Severity: important Tags: security Hi OpenStack Team! the following vulnerability was published for keystone. CVE-2013-0270[0]: Large HTTP request DoS If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelo