[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*


CVE-2013-4347
The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack.

CVE-2013-4346
The Server.verify_request function in SimpleGeo python-oauth2 does not check the nonce, which allows remote attackers to perform replay attacks via a signed URL.

*OVAL
oval:org.secpod.oval:def:1600011
CPE    3
cpe:/a:urbanairship:python-oauth2
cpe:/o:amazon:linux
cpe:/a:urbanairship:python-oauth2:-

© SecPod Technologies