Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20130603182437.GM1472@yuggoth.org>
Date: Mon, 3 Jun 2013 18:24:39 +0000
From: Jeremy Stanley <fungi@...goth.org>
To: oss-security@...ts.openwall.com, openstack@...ts.launchpad.net
Subject: Re: [OSSA 2013-013] Keystone client local information disclosure
 (CVE-2013-2013)

On 2013-06-03 10:51:19 -0700 (-0700), Lloyd Dewolf wrote:
[...]
> Interestingly, the OSSA 2013-014 notice did include
> "python-keystoneclient fix (will be included in upcoming 0.2.4
> release)".

I'm going to chalk that up to Thierry knowing the version number at
that point, since the OSSA 2013-014 fix is what got tagged with
0.2.4 the next morning. On the other hand the -013 fix was a
lower-priority feature enhancement and I didn't want to rely on a
versioning guess a week ahead. Client releases are handled a bit
more independently compared to OpenStack server components (where we
can predict release milestone dates fairly accurately).

As a general rule I'm going to try to include the release version
numbers in advance when I can do so safely, and otherwise rely on
subsequent release announcements.
-- 
Jeremy Stanley

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.