CVE-2014-0162
Published: 27 April 2014
The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to execute arbitrary commands via a crafted location.
Priority
Status
Package | Release | Status |
---|---|---|
glance Launchpad, Ubuntu, Debian |
Upstream |
Released
(2014.1, 2013.2.3)
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
(trusty was not-affected [1:2014.1-0ubuntu1])
|
|
Patches: Upstream: https://review.openstack.org/#/c/86626/ (havana) Upstream: https://review.openstack.org/#/c/86622/ (master/icehouse) |
Notes
Author | Note |
---|---|
jdstrand | fixed in 1:2013.2.3-0ubuntu1 in saucy-updates. Needs a no-change rebuild for saucy-security |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0162
- http://www.openwall.com/lists/oss-security/2014/04/10/13
- https://usn.ubuntu.com/usn/usn-2193-1
- NVD
- Launchpad
- Debian