Re: [SECURITY] [DLA 520-1] horizon security update

2016-06-19 Thread Chris Lamb
> All of Openstack is no longer support in Wheezy LTS. Please > don't spend time on unsupported packages. D'oh. I was aware of Openstack being unsupported, but somehow (!) didn't connect Horizon of being part of it.. Regards, -- ,''`. : :' : Chris Lamb `. `'`

Re: [SECURITY] [DLA 520-1] horizon security update

2016-06-19 Thread Raphael Hertzog
Hi, On Sat, 18 Jun 2016, Chris Lamb wrote: > Package: horizon > Version: 2012.1.1-10+deb7u1 > CVE ID : CVE-2016-4428 > > It was discovered that there was an XSS vulnerability in horizon, > a Django module providing web interaction with OpenStack.

[SECURITY] [DLA 520-1] horizon security update

2016-06-18 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: horizon Version: 2012.1.1-10+deb7u1 CVE ID : CVE-2016-4428 It was discovered that there was an XSS vulnerability in horizon, a Django module providing web interaction with OpenStack. For Debian 7 "Wheezy", this