Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 13.04 USN-2005-1 Critical: Cinder DoS and Data Exposure

ubuntu
Calendar Grey October 23, 2013
Scroller Ubuntu
Security weaknesses in Cinder for Ubuntu 13.04 lead to system failures and risk of data leakage. Consult USN-2005-1 for information on remedial measures.
Cinder could be made to crash or expose sensitive information.

Summary

Cinder could be made to crash or expose sensitive information.

Software Description:

- cinder: OpenStack storage service

Details:

Rongze Zhu discovered that the Cinder LVM driver did not zero out data

when deleting snapshots. This could expose sensitive information to

authenticated users when subsequent servers use the volume. (CVE-2013-4183)

Grant Murphy discovered that Cinder would allow XML entity processing. A

remote unauthenticated attacker could exploit this using the Cinder API to

cause a denial of service via resource exhaustion. (CVE-2013-4179,

CVE-2013-4202)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
  python-cinder                   1:2013.1.3-0ubuntu2.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2005-1

CVE-2013-4179, CVE-2013-4183, CVE-2013-4202

Severity
critical
Lowest
Low
Medium
High
Critical

=========================================================================Ubuntu Security Notice USN-2005-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.