You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa OpenStack Glance

Sigurnosni nedostaci programskog paketa OpenStack Glance

==========================================================================
Ubuntu Security Notice USN-3446-1
October 11, 2017

glance vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in OpenStack Glance.

Software Description:
– glance: OpenStack Image Registry and Delivery Service

Details:

Hemanth Makkapati discovered that OpenStack Glance incorrectly handled
access restrictions. A remote authenticated user could use this issue to
change the status of images, contrary to access restrictions.
(CVE-2015-5251)

Mike Fedosin and Alexei Galkin discovered that OpenStack Glance incorrectly
handled the storage quota. A remote authenticated user could use this issue
to consume disk resources, leading to a denial of service. (CVE-2015-5286)

Erno Kuvaja discovered that OpenStack Glance incorrectly handled the
show_multiple_locations option. When show_multiple_locations is enabled,
a remote authenticated user could change an image status and upload new
image data. (CVE-2016-0757)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
glance-common 1:2014.1.5-0ubuntu1.1

In general, a standard system update will make all the necessary changes.

References:
https://www.ubuntu.com/usn/usn-3446-1
CVE-2015-5251, CVE-2015-5286, CVE-2016-0757

Package Information:
https://launchpad.net/ubuntu/+source/glance/1:2014.1.5-0ubuntu1.1

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQIcBAEBCgAGBQJZ3htbAAoJEGVp2FWnRL6TG6AP/A/bgrLmpZkEH7Q21ygggpZp
BN0Onfz02oSjDLNlUNddr0mjNIOq97ATlfn881yjRrZXSO1yeFBkQnBmrwBvaRSo
N5dm23DtzPANc9Ni9XIW5KvjxMDCDTkcx1wmTzJ/xrAhWv8jnCA+awpWBOnH5xDr
UVVEf5iTvLxtMZqW3lRf+yiSQ2imFXJ4ly2DBvASnTAZ96Emp5xtLE5E3uMazfPb
kLnd7JwCzpHnneZqJUKzU6sTYeTkaPejmpDQ/qHmuAtUQ84/jOuwqwBeH0UBSKq3
ecZIdLea9eqRYTfphG5J6aGfOq08ddcLxo5f1kiewHcVt5WdgOO7rcDMUhmT9Oxc
EL5JNdkS5zaU7jIlAP2jZluIyzFyPse/6SFg9wZFn7adPqfbzvC1r0bKMqUah6DI
nIm6DtfEcG0mPF0WAVE46ah7ryemVoaT6c9SGv2f21paRZsraxFxnDAgZaf3rPYU
1oQ/C/mnzGsRlauK7vV7cyhpDoVx7JwpvLDistj6HAu7wmpEEWW+OHqU3DTqpcab
1C5m4vVP+kBA/COuIxJlBtXzxd/nx8pWvHbdo/uLoZCk1Up72DKTUEiQG8eVk3U6
iP1tmrzPlCNepAccU6rH+A35Sv15BTSm7d4i3W0plRLHzVuSh7S8zVxOAcsHpCtk
NkNdrqeicokSqGVH+mNU
=waPV
—–END PGP SIGNATURE—–

Top
More in Preporuke
Sigurnosni nedostatak programskog paketa OpenStack Keystone

Otkriven je sigurnosni nedostatak u programskom paketu OpenStack Keystone za operacijski sustav Ubuntu 16.04 LTS. Otkriveni nedostatak potencijalnim napadačima omogućuje...

Close