ossa/ossa/OSSA-2014-012.yaml

62 lines
1.4 KiB
YAML

date: 2014-04-10
id: OSSA-2014-012
title: 'Remote code execution in Glance Sheepdog backend'
description: 'Paul McMillan from Nebula reported a vulnerability in Glance Sheepdog
backend. By using a specially crafted location, a user allowed to insert or modify
Glance image metadata may trigger code execution on the Glance host as the user
the Glance service runs under. This may result in Glance host unauthorized access
and further compromise of the Glance service. All setups using Glance server with
the (enabled by default) sheepdog backend are affected.'
reference: http://lists.openstack.org/pipermail/openstack-announce/2014-April/000220.html
affected-products:
- product: glance
version: from 2013.2 to 2013.2.3
vulnerabilities:
- cve-id: CVE-2014-0162
impact-assessment:
source: 'Red Hat Product Security'
rating: important
assessment:
type: CVSS2
score: 6.5
detail: AV:N/AC:L/Au:S/C:P/I:P/A:P
classification:
source: 'Red Hat Product Security'
type: CWE
detail: TODO
reporters:
- name: 'Paul McMillan'
affiliation: Nebula
reported:
- CVE-2014-0162
issues:
links:
- https://launchpad.net/bugs/1298698
type: launchpad
reviews:
juno:
- https://review.openstack.org/#/c/86622
icehouse:
- https://review.openstack.org/#/c/86625
havana:
- https://review.openstack.org/#/c/86626
type: gerrit