REDHAT-BUG-845106: Medium severity red hat openstack services on openshift vulnerability
Thierry Carrez <thierry> reports:
Pádraig Brady from Red Hat discovered that the fix implemented for CVE-2012-3361 (OSSA-2012-008) was not covering all attack scenarios. By crafting a malicious image with root-readable-only symlinks and requesting a server based on it, an authenticated user could still corrupt arbitrary files (all setups affected) or inject arbitrary files (Essex and later setups with OpenStack API enabled and a libvirt-based hypervisor) on the host filesystem, potentially resulting in full compromise of that compute node.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-845106?
The severity of REDHAT-BUG-845106 is classified as a critical vulnerability.
How do I fix REDHAT-BUG-845106?
To fix REDHAT-BUG-845106, apply the latest updates for Red Hat OpenStack and Red Hat libvirt as soon as they are available.
What products are affected by REDHAT-BUG-845106?
REDHAT-BUG-845106 affects Red Hat OpenStack and Red Hat libvirt.
What type of attack does REDHAT-BUG-845106 relate to?
REDHAT-BUG-845106 relates to vulnerabilities in handling malicious images that could lead to privilege escalation.
Who discovered the issue in REDHAT-BUG-845106?
The issue in REDHAT-BUG-845106 was discovered by Pádraig Brady from Red Hat.