Date: Tue, 04 Nov 2014 17:21:47 -0700 From: Kurt Seifried <kseifried@...hat.com> To: oss-security@...ts.openwall.com Subject: Re: CVE Request for requests-kerberos On 04/11/14 11:20 AM, Ian Cordasco wrote: > Hello all, > > A fix was merged and released today for the package which performs > kerberos authentication when using python-requests. Prior to this, > every version of the package did not properly handle mutual > authentication which means that the client did not verify that the > user was communicating with a trusted server. The version which > contains the fix is 0.6 and all prior versions are considered > vulnerable. Can you please provide a link to said package/release/commit/etc? Thanks. > Please assign a CVE to this issue. > > Cheers, > Ian > -- Kurt Seifried -- Red Hat -- Product Security -- Cloud PGP A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993 Download attachment "signature.asc" of type "application/pgp-signature" (820 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.