Login
Newsletter
Werbung

Sicherheit: Mangelnde Rechteprüfung in OpenStack
Aktuelle Meldungen Distributionen
Name: Mangelnde Rechteprüfung in OpenStack
ID: USN-1709-1
Distribution: Ubuntu
Plattformen: Ubuntu 11.10, Ubuntu 12.04 LTS, Ubuntu 12.10
Datum: Mi, 30. Januar 2013, 08:41
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0208
https://launchpad.net/ubuntu/+source/nova/2012.1.3+stable-20120827-4d2a4afe-0ubuntu1.1
https://launchpad.net/ubuntu/+source/nova/2012.2.1+stable-20121212-a99a802e-0ubuntu1.1
Applikationen: OpenStack

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--===============0841320380423817188==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="------------enigB853EE88C5B9573A44865034"

This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--------------enigB853EE88C5B9573A44865034
Content-Type: text/plain; charset=ISO-8859-
Content-Transfer-Encoding: quoted-printable


==========================================================================
Ubuntu Security Notice USN-1709-1
January 29, 2013

nova vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.10
- Ubuntu 12.04 LTS
- Ubuntu 11.10

Summary:

Nova volume could be made to expose volumes from other users.

Software Description:
- nova: OpenStack Compute cloud infrastructure

Details:

Phil Day discovered that nova-volume did not validate access to volumes. An
authenticated attacker could exploit this to bypass intended access
controls and boot from arbitrary volumes.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
nova-volume
2012.2.1+stable-20121212-a99a802e-0ubuntu1.1
python-nova
2012.2.1+stable-20121212-a99a802e-0ubuntu1.1

Ubuntu 12.04 LTS:
nova-volume
2012.1.3+stable-20120827-4d2a4afe-0ubuntu1.1
python-nova
2012.1.3+stable-20120827-4d2a4afe-0ubuntu1.1

Ubuntu 11.10:
nova-volume 2011.3-0ubuntu6.11
python-nova 2011.3-0ubuntu6.11

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1709-1
CVE-2013-0208

Package Information:

https://launchpad.net/ubuntu/+source/nova/2012.2.1+stable-20121212-a99a802e-0ubuntu1.1

https://launchpad.net/ubuntu/+source/nova/2012.1.3+stable-20120827-4d2a4afe-0ubuntu1.1
https://launchpad.net/ubuntu/+source/nova/2011.3-0ubuntu6.11





--------------enigB853EE88C5B9573A44865034
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with undefined - http://www.enigmail.net/

iQIcBAEBCgAGBQJRCFnZAAoJEFHb3FjMVZVz9+EQAIF4a2hfYvnSX0Z8pRYVWRDl
yBDp2mG8E05O3CK8daxKTKg+1tmrMm/gMx8BBRtc/6PFNqD20dWTqPp1HtNFUNvW
sZjFETbNAfhWRD23jt2fOXF3Gev5Etnz1GxUcoakNhnAPBpZrZfLNwnuL3ZEmTlj
CeU1G8FxQ/mWO4ZFAm/iZK9+XrXm1VPBcFqt8aGCfLVYjh6ZspyJLZ+VPY0le010
vStnNCswH4CogRXgCi/vu9uzijrlzk2ATDbN73zrNYzhwIjaoCGex45Ho3j4yTcq
89uc4qpNlu3yAIL5j8J/ruUnq2HN3SP9dHJw8xMcGeQFb7RWsKpuKW+mW9drxk0K
3DcHTJUr/dU4EYz8GkarvMiOqwTBdng+ADuRinV0OXcp3aCS0jxAAxXlCA4A2VYt
3lwL+xmTanSh2SfikEtwfMGP/epORawbN3567gfYmZmE+Z/QdaBo3Ri80xrTM9Y0
/B2ZPX0uBfJL14hRwexU5TeIAdpWaN2JuSJ6X/WJJFASue5oSy0gXbw2SaiyWkgD
Tl3Nh5iXaEnV3c3sjjctmqXYG4mxyc4vjhtp4o+T/FFkEbJjcvVY/WNsn5Smni8a
wEizUd07pd227rK1F/zr2Pf/phbCtJxRPeNziOKgQRvDrSp9eoI+OwqbHKxDYAY1
hPlmt48VVUYrnqAXlsSU
=05hF
-----END PGP SIGNATURE-----

--------------enigB853EE88C5B9573A44865034--


--===============0841320380423817188==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============0841320380423817188==--
Pro-Linux
Gewinnspiel
Neue Nachrichten
Werbung