Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAN-Kwu1Quk6N5fa39Gf1q75YPKD-dDZB=hXbaw8RTkgE5eKEHg@mail.gmail.com>
Date: Tue, 4 Nov 2014 18:30:30 -0600
From: Ian Cordasco <graffatcolmingov@...il.com>
To: oss-security@...ts.openwall.com
Subject: Re: CVE Request for requests-kerberos

On Tue, Nov 4, 2014 at 6:21 PM, Kurt Seifried <kseifried@...hat.com> wrote:
> On 04/11/14 11:20 AM, Ian Cordasco wrote:
>> Hello all,
>>
>> A fix was merged and released today for the package which performs
>> kerberos authentication when using python-requests. Prior to this,
>> every version of the package did not properly handle mutual
>> authentication which means that the client did not verify that the
>> user was communicating with a trusted server. The version which
>> contains the fix is 0.6 and all prior versions are considered
>> vulnerable.
>
> Can you please provide a link to said package/release/commit/etc? Thanks.
>
>> Please assign a CVE to this issue.
>>
>> Cheers,
>> Ian
>>
>
> --
> Kurt Seifried -- Red Hat -- Product Security -- Cloud
> PGP A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993
>

Sure,

https://github.com/requests/requests-kerberos/pull/36 is the pull
request adding https://github.com/mkomitee/requests-kerberos/commit/9c1e08cc17bb6950455a85d33d391ecd2bce6eb6.
This is released in https://pypi.python.org/pypi/requests-kerberos

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.