RE: [CVE-2014-7807] Apache CloudStack unauthenticated LDAP binds

2014-12-10 Thread Giles Sirett
2055 giles.sir...@shapeblue.com -Original Message- From: sebgoa [mailto:run...@gmail.com] Sent: 10 December 2014 09:10 To: users@cloudstack.apache.org Subject: Re: [CVE-2014-7807] Apache CloudStack unauthenticated LDAP binds On Dec 9, 2014, at 11:56 PM, esander...@hushmail.com wrote: > Daa

Re: [CVE-2014-7807] Apache CloudStack unauthenticated LDAP binds

2014-12-10 Thread sebgoa
epository: http://shapeblue.com/packages >> Release notes: >> > https://github.com/shapeblue/cloudstack/wiki/Apache-CloudStack-4.3.1-ShapeBlue-Patch02 >> Source tag 4.3.1-shapeblue-02: >> > https://github.com/shapeblue/cloudstack/releases/tag/shapeblue-4.3.1-02 >> >&

Re: [CVE-2014-7807] Apache CloudStack unauthenticated LDAP binds

2014-12-09 Thread esanders83
/packages >> Release notes: >> > https://github.com/shapeblue/cloudstack/wiki/Apache-CloudStack-4.3.1-ShapeBlue-Patch02 >> Source tag 4.3.1-shapeblue-02: >> > https://github.com/shapeblue/cloudstack/releases/tag/shapeblue-4.3.1-02 >> >> Regards. >&

Re: [CVE-2014-7807] Apache CloudStack unauthenticated LDAP binds

2014-12-09 Thread Daan Hoogland
apeblue-02: >> > https://github.com/shapeblue/cloudstack/releases/tag/shapeblue-4.3.1-02 >> >> Regards. >> >>> On 09-Dec-2014, at 1:41 am, John Kinsella wrote: >>> >>> -BEGIN PGP SIGNED MESSAGE- >>> Hash: SHA512 >>> >

Re: [CVE-2014-7807] Apache CloudStack unauthenticated LDAP binds

2014-12-09 Thread esanders83
https://github.com/shapeblue/cloudstack/releases/tag/shapeblue-4.3.1-02 > > Regards. > >> On 09-Dec-2014, at 1:41 am, John Kinsella wrote: >> >> -BEGIN PGP SIGNED MESSAGE- >> Hash: SHA512 >> >> CVE-2014-7807: Apache CloudStack unauthen

Re: [CVE-2014-7807] Apache CloudStack unauthenticated LDAP binds

2014-12-09 Thread Daan Hoogland
t; https://github.com/shapeblue/cloudstack/releases/tag/shapeblue-4.3.1-02 > > Regards. > >> On 09-Dec-2014, at 1:41 am, John Kinsella wrote: >> >> -BEGIN PGP SIGNED MESSAGE- >> Hash: SHA512 >> >> CVE-2014-7807: Apache CloudStack unauthenticat

Re: [CVE-2014-7807] Apache CloudStack unauthenticated LDAP binds

2014-12-09 Thread esanders83
blue/cloudstack/wiki/Apache-CloudStack-4.3.1-ShapeBlue-Patch02 Source tag 4.3.1-shapeblue-02: https://github.com/shapeblue/cloudstack/releases/tag/shapeblue-4.3.1-02 Regards. > On 09-Dec-2014, at 1:41 am, John Kinsella wrote: > > -BEGIN PGP SIGNED MESSAGE----- > Hash: SHA512 > >

Re: [CVE-2014-7807] Apache CloudStack unauthenticated LDAP binds

2014-12-09 Thread Rohit Yadav
D MESSAGE- > Hash: SHA512 > > CVE-2014-7807: Apache CloudStack unauthenticated LDAP binds > > CVSS: > 7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P > > Vendors: > The Apache Software Foundation > Citrix, Inc. > > Versions Afffected: > Apache CloudStack 4.3, 4.4 > >

[CVE-2014-7807] Apache CloudStack unauthenticated LDAP binds

2014-12-08 Thread John Kinsella
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 CVE-2014-7807: Apache CloudStack unauthenticated LDAP binds CVSS: 7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P Vendors: The Apache Software Foundation Citrix, Inc. Versions Afffected: Apache CloudStack 4.3, 4.4 Description: Apache CloudStack may be