[Openstack-devel] Bug#731833: New upstream release, fixes security bug

Juan J. Martinez juan at memset.com
Tue Dec 10 10:25:30 UTC 2013


Package: python-ftp-cloudfs
Version: 0.23.1-2

Since 0.23.1 (2013-09-08), several version have been released. Some of
them add functionalities and the unmaintained python-cloudfiles has been
replaced by python-swiftclient, but 0.25.2 fixes a security bug; from
the ChangeLog:

Fixed a bug in ObjectStorageFS when used in "delayed authentication"
mode that resulted in a information leak vulnerability in sftp-cloudfs.

Under certain conditions it was possible to serve a cached directory
listing from a different user.

It is recommended to upgrade to version 0.25.2.

Regards,

Juan

-- 
Juan J. Martinez
Software Developer, MEMSET

mail: juan at memset.com
 web: http://www.memset.com/

Memset Ltd., registration number 4504980.
Building 87, Dunsfold Park, Stovolds Hill, Cranleigh, Surrey GU6 8TB, UK.



More information about the Openstack-devel mailing list