Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
OpenStack Glance could be made to run programs as the glance user if it
processed a specially crafted request.
Software Description:
- glance: OpenStack Image Registry and Delivery Service
Details:
Paul McMillan discovered that the Sheepdog backend in OpenStack Glance did
not properly handle untrusted input. A remote authenticated attacker
exploit this to execute arbitrary commands as the glance user.
The problem can be corrected by updating your system to the following package versions: Ubuntu 13.10: python-glance 1:2013.2.3-0ubuntu1.1 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-2193-1
CVE-2014-0162
Get the latest Linux and open source security news straight to your inbox.