Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 14.04 LTS OpenStack USN-2325-1 Critical Timing Attack

ubuntu
Calendar Grey August 21, 2014
Scroller Ubuntu
A security flaw in OpenStack Nova on Ubuntu might result in sensitive data being exposed. It is advised to apply updates for enhanced security.
OpenStack Nova could be made to expose sensitive information over the network.

Summary

OpenStack Nova could be made to expose sensitive information over the

network.

Software Description:

- nova: OpenStack Compute cloud infrastructure

Details:

Alex Gaynor discovered that OpenStack Nova would sometimes respond with

variable times when comparing authentication tokens. If nova were

configured to proxy metadata requests via Neutron, a remote authenticated

attacker could exploit this to conduct timing attacks and ascertain

configuration details of another instance.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
  python-nova                     1:2014.1.2-0ubuntu1.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2325-1

CVE-2014-3517

Severity
critical
Lowest
Low
Medium
High
Critical

=========================================================================Ubuntu Security Notice USN-2325-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.