Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
OpenStack Nova could be made to expose sensitive information over the
network.
Software Description:
- nova: OpenStack Compute cloud infrastructure
Details:
Alex Gaynor discovered that OpenStack Nova would sometimes respond with
variable times when comparing authentication tokens. If nova were
configured to proxy metadata requests via Neutron, a remote authenticated
attacker could exploit this to conduct timing attacks and ascertain
configuration details of another instance.
The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: python-nova 1:2014.1.2-0ubuntu1.1 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-2325-1
CVE-2014-3517
Get the latest Linux and open source security news straight to your inbox.