2055
giles.sir...@shapeblue.com
-Original Message-
From: sebgoa [mailto:run...@gmail.com]
Sent: 10 December 2014 09:10
To: users@cloudstack.apache.org
Subject: Re: [CVE-2014-7807] Apache CloudStack unauthenticated LDAP binds
On Dec 9, 2014, at 11:56 PM, esander...@hushmail.com wrote:
> Daa
epository: http://shapeblue.com/packages
>> Release notes:
>>
> https://github.com/shapeblue/cloudstack/wiki/Apache-CloudStack-4.3.1-ShapeBlue-Patch02
>> Source tag 4.3.1-shapeblue-02:
>>
> https://github.com/shapeblue/cloudstack/releases/tag/shapeblue-4.3.1-02
>>
>&
/packages
>> Release notes:
>>
>
https://github.com/shapeblue/cloudstack/wiki/Apache-CloudStack-4.3.1-ShapeBlue-Patch02
>> Source tag 4.3.1-shapeblue-02:
>>
>
https://github.com/shapeblue/cloudstack/releases/tag/shapeblue-4.3.1-02
>>
>> Regards.
>&
apeblue-02:
>>
> https://github.com/shapeblue/cloudstack/releases/tag/shapeblue-4.3.1-02
>>
>> Regards.
>>
>>> On 09-Dec-2014, at 1:41 am, John Kinsella wrote:
>>>
>>> -BEGIN PGP SIGNED MESSAGE-
>>> Hash: SHA512
>>>
>
https://github.com/shapeblue/cloudstack/releases/tag/shapeblue-4.3.1-02
>
> Regards.
>
>> On 09-Dec-2014, at 1:41 am, John Kinsella wrote:
>>
>> -BEGIN PGP SIGNED MESSAGE-
>> Hash: SHA512
>>
>> CVE-2014-7807: Apache CloudStack unauthen
t; https://github.com/shapeblue/cloudstack/releases/tag/shapeblue-4.3.1-02
>
> Regards.
>
>> On 09-Dec-2014, at 1:41 am, John Kinsella wrote:
>>
>> -BEGIN PGP SIGNED MESSAGE-
>> Hash: SHA512
>>
>> CVE-2014-7807: Apache CloudStack unauthenticat
blue/cloudstack/wiki/Apache-CloudStack-4.3.1-ShapeBlue-Patch02
Source tag 4.3.1-shapeblue-02:
https://github.com/shapeblue/cloudstack/releases/tag/shapeblue-4.3.1-02
Regards.
> On 09-Dec-2014, at 1:41 am, John Kinsella wrote:
>
> -BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA512
>
>
D MESSAGE-
> Hash: SHA512
>
> CVE-2014-7807: Apache CloudStack unauthenticated LDAP binds
>
> CVSS:
> 7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P
>
> Vendors:
> The Apache Software Foundation
> Citrix, Inc.
>
> Versions Afffected:
> Apache CloudStack 4.3, 4.4
>
>
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512
CVE-2014-7807: Apache CloudStack unauthenticated LDAP binds
CVSS:
7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P
Vendors:
The Apache Software Foundation
Citrix, Inc.
Versions Afffected:
Apache CloudStack 4.3, 4.4
Description:
Apache CloudStack may be