USN-5835-2: OpenStack Glance vulnerability
Guillaume Espanel, Pierre Libeau, Arnaud Morin, and Damien Rannou discovered that OpenStack Glance incorrectly handled VMDK image processing. An authenticated attacker could possibly supply a specially crafted VMDK flat image and obtain arbitrary files from the server containing sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-5835-2?
The severity of USN-5835-2 is considered high due to its potential for unauthorized access to files.
How do I fix USN-5835-2?
To fix USN-5835-2, update the glance-common package to the latest version compatible with your Ubuntu release.
What products are affected by USN-5835-2?
The affected products by USN-5835-2 are various versions of Ubuntu that include the glance-common package.
Who discovered the vulnerability related to USN-5835-2?
The vulnerability related to USN-5835-2 was discovered by Guillaume Espanel, Pierre Libeau, Arnaud Morin, and Damien Rannou.
What type of attack does USN-5835-2 protect against?
USN-5835-2 protects against attacks where an authenticated user could exploit VMDK image processing to access arbitrary files.