Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 13.10 USN-2193-1 Critical: Glance Command Execution

ubuntu
Calendar Grey May 5, 2014
Scroller Ubuntu
The Glance security flaw permits unauthorized remote access for command execution. Detailed upgrade procedures for Ubuntu 13.10 are available.
OpenStack Glance could be made to run programs as the glance user if it processed a specially crafted request.

Summary

OpenStack Glance could be made to run programs as the glance user if it

processed a specially crafted request.

Software Description:

- glance: OpenStack Image Registry and Delivery Service

Details:

Paul McMillan discovered that the Sheepdog backend in OpenStack Glance did

not properly handle untrusted input. A remote authenticated attacker

exploit this to execute arbitrary commands as the glance user.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  python-glance                   1:2013.2.3-0ubuntu1.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2193-1

CVE-2014-0162

Severity
critical
Lowest
Low
Medium
High
Critical

=========================================================================Ubuntu Security Notice USN-2193-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.