CVE-2012-6639: Critical severity Canonical cloud-init vulnerability
An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2012-6639?
CVE-2012-6639 is a privilege elevation vulnerability in Cloud-init before version 0.7.0.
What is the severity of CVE-2012-6639?
The severity of CVE-2012-6639 is critical with a CVSS score of 8.8.
How does CVE-2012-6639 affect Cloud-init?
CVE-2012-6639 affects Cloud-init versions before 0.7.0 and allows for privilege elevation when making requests to an untrusted system for EC2 instance data.
Which software packages are affected by CVE-2012-6639?
Cloud-init packages from Debian, Canonical Cloud-init, and various versions of Debian Linux and SUSE Linux Enterprise Server are affected by CVE-2012-6639.
Where can I find more information about CVE-2012-6639?
You can find more information about CVE-2012-6639 at the following references: http://article.gmane.org/gmane.comp.security.oss.general/12299, https://security-tracker.debian.org/tracker/CVE-2012-6639, and http://www.openwall.com/lists/oss-security/2014/03/06/7