=========================================================================Ubuntu Security Notice USN-2194-1
May 05, 2014

neutron vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.10

Summary:

OpenStack Neutron would allow unintended access to other tenant networks.

Software Description:
- neutron: Openstack Virtual Network Service

Details:

Aaron Rosen discovered that OpenStack Neutron did not properly perform
authorization checks when creating ports when using plugins relying on the
l3-agent. A remote authenticated attacker could exploit this to access the
network of other tenants.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  python-neutron                  1:2013.2.3-0ubuntu1.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2194-1
  CVE-2014-0056

Package Information:
  https://launchpad.net/ubuntu/+source/neutron/1:2013.2.3-0ubuntu1.1




Ubuntu 2194-1: OpenStack Neutron vulnerability

May 5, 2014
OpenStack Neutron would allow unintended access to other tenant networks.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 13.10: python-neutron 1:2013.2.3-0ubuntu1.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2194-1

CVE-2014-0056

Severity
=========================================================================Ubuntu Security Notice USN-2194-1

Package Information

https://launchpad.net/ubuntu/+source/neutron/1:2013.2.3-0ubuntu1.1

Related News