Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in OpenStack Nova.
Software Description:
- nova: OpenStack Compute cloud infrastructure
Details:
Darragh O'Reilly discovered that OpenStack Nova did not properly set up its
sudo configuration. If a different flaw was found in OpenStack Nova, this
vulnerability could be used to escalate privileges. This issue only
affected Ubuntu 13.10 and Ubuntu 14.04 LTS. (CVE-2013-1068)
Bernhard M. Wiedemann and Pedraig Brady discovered that OpenStack Nova did
not properly verify the virtual size of a QCOW2 images. A remote
authenticated attacker could exploit this to create a denial of service via
disk consumption. This issue did not affect Ubuntu 14.04 LTS.
(CVE-2013-4463, CVE-2013-4469)
JuanFra Rodriguez Cardoso discovered that OpenStack Nova did not enforce
SSL connections when Nova was configured to use QPid and qpid_protocol is
set to 'ssl'. If a remote attacker were able to perform a man-in-the-middle
attack, this flaw could be ...
The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: python-nova 1:2014.1-0ubuntu1.2 Ubuntu 13.10: python-nova 1:2013.2.3-0ubuntu1.2 Ubuntu 12.04 LTS: python-nova 2012.1.3+stable-20130423-e52e6912-0ubuntu1.4 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-2247-1
CVE-2013-1068, CVE-2013-4463, CVE-2013-4469, CVE-2013-6491,
CVE-2013-7130, CVE-2014-0134, CVE-2014-0167
Get the latest Linux and open source security news straight to your inbox.