Login
Newsletter
Werbung

Sicherheit: Überschreiben von Dateien in Nova
Aktuelle Meldungen Distributionen
Name: Überschreiben von Dateien in Nova
ID: USN-1305-1
Distribution: Ubuntu
Plattformen: Ubuntu 11.10
Datum: Di, 13. Dezember 2011, 19:42
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4596
Applikationen: Nova

Originalnachricht


--===============2605124455448729482==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-UmxwanQcf2/6nZ061Oho"


--=-UmxwanQcf2/6nZ061Oho
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1305-1
December 13, 2011

nova vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.10

Summary:

Nova could be made to overwrite files.

Software Description:
- nova: OpenStack Compute cloud infrastructure

Details:

David Black discovered that Nova did not properly perform input validation
during image registration. An attacker could exploit this by registering a
crafted image using the EC2 API or S3/RegisterImage method and overwrite
files as the nova user.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
python-nova 2011.3-0ubuntu6.3

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1305-1
CVE-2011-4596

Package Information:
https://launchpad.net/ubuntu/+source/nova/2011.3-0ubuntu6.3



--ÞmxwanQcf2/6nZ061Oho
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJO54TRAAoJEFHb3FjMVZVzUpwQAIwzAeQGJT4bcmVMmswcF6Lf
uGvxt1DYsBsa0xzrPVBtrYhqVpLNNPNpVaBZrcXFk6TPYEMQJoWXBZ2I2VXcvIny
oM47KnBEQETy/W1DIczYMfCwDjispHJtQsvvxagmD2jmepGgSNStpWav3ovkkR5M
sGe6tAsyp+hx1IFVPwZiahST5OqVg13bWk3eiR1jBTpMnDibKQWSEKV1dWxWSQEo
i/snRu3y/LSZc7gZyDX/IEyIrY2ny9/i/tnLR+78WGKyZ1A7razkV3ncimUxrxPy
3OmikQFZkjPNFwuCuzprVUKVHDsPMiVAYjpLMPAltCSDfaIV8RwxnSMfVXUl8ZE+
hEW12TBBTZnNyL/h/4VeoJlESGUnxRdSKItha6tskgw9iONwE4UwQrrydszFwDQX
PfLfaUkNZLwtV8SJvVyuhDR2XSFMkwUNE1C71bZDPL6PYl/wRIdTYxmbhTMFjnyL
1b64JuX7njZ+6EzBP04cMPv5eXYBEM+utbTIsO/jgZm2zknOLZzFUAQds0B4YYmT
7ivHwahS/duglK3Z2H3WfZH5jZZOyPSK3OJ9MfbPGmIXNaj+pZxhunCdBzik1yBp
w2rZ6H5Y8SeH1yYRcqNPTCH+wiRIPh/H+akZqk7J8vJ2f/dk6WEnil+99d7dEoWJ
7CF1MMhFTj6/Batl0sre
=oTF6
-----END PGP SIGNATURE-----

--=-UmxwanQcf2/6nZ061Oho--



--===============2605124455448729482==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============2605124455448729482==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung