USN-5835-1: Cinder vulnerability
Guillaume Espanel, Pierre Libeau, Arnaud Morin, and Damien Rannou discovered that Cinder incorrectly handled VMDK image processing. An authenticated attacker could possibly supply a specially crafted VMDK flat image and obtain arbitrary files from the server containing sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-5835-1?
USN-5835-1 is classified as a high severity vulnerability due to the potential for an authenticated attacker to access sensitive information.
How do I fix USN-5835-1?
To fix USN-5835-1, you should upgrade to the latest patched version of python3-cinder listed in the advisory for your Ubuntu version.
What systems are affected by USN-5835-1?
USN-5835-1 affects Ubuntu versions 22.10, 22.04, and 20.04 that have specific versions of python3-cinder installed.
What is the nature of the vulnerability described in USN-5835-1?
The vulnerability in USN-5835-1 involves improper handling of VMDK image processing which may lead to unauthorized file access.
Who discovered the vulnerability referenced in USN-5835-1?
The vulnerability in USN-5835-1 was discovered by researchers Guillaume Espanel, Pierre Libeau, Arnaud Morin, and Damien Rannou.