Lucene search

K
redhatRedHatRHSA-2015:0042
HistoryJan 13, 2015 - 5:52 p.m.

(RHSA-2015:0042) Low: cloud-init security, bug fix, and enhancement update

2015-01-1317:52:12
access.redhat.com
22

0.053 Low

EPSS

Percentile

93.1%

The cloud-init packages provide a set of init scripts for cloud instances.
Cloud instances need special scripts to run during initialization to
retrieve and install ssh keys and to let the user run various scripts.

A denial of service flaw was found in the way Python’s SSL module
implementation performed matching of certain certificate names. A remote
attacker able to obtain a valid certificate that contained multiple
wildcard characters could use this flaw to issue a request to validate such
a certificate, resulting in excessive consumption of CPU. (CVE-2013-2099)

This issue was discovered by Florian Weimer of Red Hat Product Security.

The cloud-init packages have been upgraded to upstream version 0.7.5, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#1111709, BZ#1119334)

All cloud-init users are advised to upgrade to these updated packages,
which correct these issues and add these enhancements.