Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 04 Nov 2014 17:21:47 -0700
From: Kurt Seifried <>
Subject: Re: CVE Request for requests-kerberos

On 04/11/14 11:20 AM, Ian Cordasco wrote:
> Hello all,
> A fix was merged and released today for the package which performs
> kerberos authentication when using python-requests. Prior to this,
> every version of the package did not properly handle mutual
> authentication which means that the client did not verify that the
> user was communicating with a trusted server. The version which
> contains the fix is 0.6 and all prior versions are considered
> vulnerable.

Can you please provide a link to said package/release/commit/etc? Thanks.

> Please assign a CVE to this issue.
> Cheers,
> Ian

Kurt Seifried -- Red Hat -- Product Security -- Cloud
PGP A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993

Download attachment "signature.asc" of type "application/pgp-signature" (820 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.