Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in OpenStack
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in OpenStack
ID: USN-3446-1
Distribution: Ubuntu
Plattformen: Ubuntu 14.04 LTS
Datum: Mi, 11. Oktober 2017, 17:40
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5251
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5286
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0757
Applikationen: OpenStack

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============2602912734907570693==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="AVoeLI39kwMNMDJf8V7Qmf6fG46RpTdcN"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--AVoeLI39kwMNMDJf8V7Qmf6fG46RpTdcN
Content-Type: multipart/mixed;
boundary="1LCxv3D1xGtsHrEB4QM93hrocfBJ7AkfV";
protected-headers="v1"
From: Marc Deslauriers <marc.deslauriers@canonical.com>
Reply-To: Ubuntu Security <security@ubuntu.com>
To: ubuntu-security-announce@lists.ubuntu.com
Message-ID: <d4dd7b7b-087c-7b5e-1fd5-e7520b04fe3c@canonical.com>
Subject: [USN-3446-1] OpenStack Glance vulnerabilities

--1LCxv3D1xGtsHrEB4QM93hrocfBJ7AkfV
Content-Type: text/plain; charset=utf-8
Content-Language: en-C
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-3446-1
October 11, 2017

glance vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in OpenStack Glance.

Software Description:
- glance: OpenStack Image Registry and Delivery Service

Details:

Hemanth Makkapati discovered that OpenStack Glance incorrectly handled
access restrictions. A remote authenticated user could use this issue to
change the status of images, contrary to access restrictions.
(CVE-2015-5251)

Mike Fedosin and Alexei Galkin discovered that OpenStack Glance incorrectly
handled the storage quota. A remote authenticated user could use this issue
to consume disk resources, leading to a denial of service. (CVE-2015-5286)

Erno Kuvaja discovered that OpenStack Glance incorrectly handled the
show_multiple_locations option. When show_multiple_locations is enabled,
a remote authenticated user could change an image status and upload new
image data. (CVE-2016-0757)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
glance-common 1:2014.1.5-0ubuntu1.1

In general, a standard system update will make all the necessary changes.

References:
https://www.ubuntu.com/usn/usn-3446-1
CVE-2015-5251, CVE-2015-5286, CVE-2016-0757

Package Information:
https://launchpad.net/ubuntu/+source/glance/1:2014.1.5-0ubuntu1.1



--1LCxv3D1xGtsHrEB4QM93hrocfBJ7AkfV--

--AVoeLI39kwMNMDJf8V7Qmf6fG46RpTdcN
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJZ3htbAAoJEGVp2FWnRL6TG6AP/A/bgrLmpZkEH7Q21ygggpZp
BN0Onfz02oSjDLNlUNddr0mjNIOq97ATlfn881yjRrZXSO1yeFBkQnBmrwBvaRSo
N5dm23DtzPANc9Ni9XIW5KvjxMDCDTkcx1wmTzJ/xrAhWv8jnCA+awpWBOnH5xDr
UVVEf5iTvLxtMZqW3lRf+yiSQ2imFXJ4ly2DBvASnTAZ96Emp5xtLE5E3uMazfPb
kLnd7JwCzpHnneZqJUKzU6sTYeTkaPejmpDQ/qHmuAtUQ84/jOuwqwBeH0UBSKq3
ecZIdLea9eqRYTfphG5J6aGfOq08ddcLxo5f1kiewHcVt5WdgOO7rcDMUhmT9Oxc
EL5JNdkS5zaU7jIlAP2jZluIyzFyPse/6SFg9wZFn7adPqfbzvC1r0bKMqUah6DI
nIm6DtfEcG0mPF0WAVE46ah7ryemVoaT6c9SGv2f21paRZsraxFxnDAgZaf3rPYU
1oQ/C/mnzGsRlauK7vV7cyhpDoVx7JwpvLDistj6HAu7wmpEEWW+OHqU3DTqpcab
1C5m4vVP+kBA/COuIxJlBtXzxd/nx8pWvHbdo/uLoZCk1Up72DKTUEiQG8eVk3U6
iP1tmrzPlCNepAccU6rH+A35Sv15BTSm7d4i3W0plRLHzVuSh7S8zVxOAcsHpCtk
NkNdrqeicokSqGVH+mNU
=waPV
-----END PGP SIGNATURE-----

--AVoeLI39kwMNMDJf8V7Qmf6fG46RpTdcN--


--===============2602912734907570693==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============2602912734907570693==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung