Описание
The Server.verify_request function in SimpleGeo python-oauth2 does not check the nonce, which allows remote attackers to perform replay attacks via a signed URL.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| python-oauth2 | removed | package | ||
| python-oauth2 | no-dsa | wheezy | package |
Примечания
https://www.openwall.com/lists/oss-security/2013/09/12/5
https://github.com/simplegeo/python-oauth2/issues/129
Связанные уязвимости
The Server.verify_request function in SimpleGeo python-oauth2 does not check the nonce, which allows remote attackers to perform replay attacks via a signed URL.
The Server.verify_request function in SimpleGeo python-oauth2 does not check the nonce, which allows remote attackers to perform replay attacks via a signed URL.
The Server.verify_request function in SimpleGeo python-oauth2 does not check the nonce, which allows remote attackers to perform replay attacks via a signed URL.
SimpleGeo python-oauth2 does not check the nonce allowing replay attacks