MGASA-2013-0314

Source
https://advisories.mageia.org/MGASA-2013-0314.html
Import Source
https://advisories.mageia.org/MGASA-2013-0314.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2013-0314
Upstream
  • CVE-2013-4347
Published
2013-10-25T20:53:17Z
Modified
2026-04-16T06:23:27.742506107Z
Summary
Updated python-oauth2 packages fix CVE-2013-4347
Details

It was found that in python-oauth2, an application for authorization flows for web applications, the nonce value generated isn't sufficiently random. While doing bulk operations the nonce might be repeated, so there is a chance of predictability. This could allow MITM attackers to conduct replay attacks. (CVE-2013-4347)

References
Credits

Affected packages

Mageia:2 / python-oauth2

Package

Name
python-oauth2
Purl
pkg:rpm/mageia/python-oauth2?arch=source&distro=mageia-2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.5.170-1.3.mga2

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0314.json"

Mageia:3 / python-oauth2

Package

Name
python-oauth2
Purl
pkg:rpm/mageia/python-oauth2?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.5.170-2.3.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0314.json"