USN-3446-1: OpenStack Glance vulnerabilities
USN-3446-1: OpenStack Glance vulnerabilities Ubuntu Security Notice USN-3446-1 11th October, 2017 glance vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were fixed in OpenStack Glance. Software description glance – OpenStack Image Registry and Delivery Service Details Hemanth Makkapati discovered that OpenStack Glance incorrectly handledaccess restrictions. A remote authenticated user could use this issue tochange the status of images, contrary to access restrictions.(CVE-2015-5251) Mike Fedosin and Alexei Galkin discovered that OpenStack Glance incorrectlyhandled the storage quota. A remote authenticated user could use this issueto consume disk resources, leading to a denial of service. (CVE-2015-5286) Erno Kuvaja discovered that OpenStack Glance incorrectly handled theshow_multiple_locations option. When show_multiple_locations is enabled,a remote authenticated user could change an image status and upload newimage data. (CVE-2016-0757) Update instructions The problem can be corrected by updating [ more… ]