First published: Tue Dec 10 2013(Updated: )
Kashyap Chamarthy <kchamart> reports: It's possible for Neutron (OpenStack networking) users to pass arbitrary config files via rootwrap[*] which allows privilege escalation by letting user add more exec directories, change configurations of commands using rootwrap, log more than what needs to be done, etc.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Neutron | >=2013.1<=2013.2.3 | |
Canonical Ubuntu Linux | =13.10 | |
Canonical Ubuntu Linux | =14.04 | |
redhat/openstack-neutron-2013.2.2 | <5 | 5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.