Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2013-6491

Published: 1 February 2014

The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.

Priority

Medium

Status

Package Release Status
cinder
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Does not exist

quantal
Released (2012.2.4-0ubuntu1.1)
saucy Not vulnerable

trusty Does not exist
(trusty was not-affected)
upstream Not vulnerable

keystone
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Not vulnerable
(code not present)
quantal Not vulnerable
(code not present)
saucy Not vulnerable

trusty Does not exist
(trusty was not-affected [code not present])
upstream Not vulnerable

neutron
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Does not exist

quantal Does not exist

saucy Not vulnerable

trusty Does not exist
(trusty was not-affected)
upstream Not vulnerable

nova
Launchpad, Ubuntu, Debian
lucid Does not exist

precise
Released (2012.1.3+stable-20130423-e52e6912-0ubuntu1.4)
quantal Ignored
(end of life, was pending)
saucy Not vulnerable
(1:2013.2~rc2-0ubuntu1)
trusty Does not exist
(trusty was not-affected [1:2014.1~b3-0ubuntu2])
upstream
Released (2013.2.b3)
Patches:
upstream: https://github.com/openstack/oslo-incubator/commit/ad04e5787a4a651e59636ae7bb28dd9a0b2ee63f
quantum
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Not vulnerable

quantal
Released (2012.2.4-0ubuntu1.1)
saucy Does not exist

trusty Does not exist

upstream Not vulnerable