First published: Tue Jan 31 2023(Updated: )
Guillaume Espanel, Pierre Libeau, Arnaud Morin, and Damien Rannou discovered that OpenStack Glance incorrectly handled VMDK image processing. An authenticated attacker could possibly supply a specially crafted VMDK flat image and obtain arbitrary files from the server containing sensitive information.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/glance-common | <2:25.0.0-0ubuntu1.1 | 2:25.0.0-0ubuntu1.1 |
Ubuntu | =22.10 | |
All of | ||
ubuntu/glance-common | <2:24.1.0-0ubuntu1.1 | 2:24.1.0-0ubuntu1.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/glance-common | <2:20.2.0-0ubuntu1.1 | 2:20.2.0-0ubuntu1.1 |
Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-5835-2 is considered high due to its potential for unauthorized access to files.
To fix USN-5835-2, update the glance-common package to the latest version compatible with your Ubuntu release.
The affected products by USN-5835-2 are various versions of Ubuntu that include the glance-common package.
The vulnerability related to USN-5835-2 was discovered by Guillaume Espanel, Pierre Libeau, Arnaud Morin, and Damien Rannou.
USN-5835-2 protects against attacks where an authenticated user could exploit VMDK image processing to access arbitrary files.