PYSEC-2012-39
Dashboard / Vulnerabilities / PYSEC-2012-39
PYSEC-2012-39
Summary:
Details: virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.
References: http://secunia.com/advisories/49802, https://review.openstack.org/#/c/9268/, https://github.com/openstack/nova/commit/b0feaffdb2b1c51182b8dce41b367f3449af5dd9, https://github.com/openstack/nova/commit/b0feaffdb2b1c51182b8dce41b367f3449af5dd9, https://bugs.launchpad.net/nova/+bug/1015531, https://github.com/openstack/nova/commit/2427d4a99bed35baefd8f17ba422cb7aae8dcca7, https://github.com/openstack/nova/commit/2427d4a99bed35baefd8f17ba422cb7aae8dcca7, http://www.securityfocus.com/bid/54278, http://www.ubuntu.com/usn/USN-1497-1, http://secunia.com/advisories/49763, https://lists.launchpad.net/openstack/msg14089.html, http://lists.fedoraproject.org/pipermail/package-announce/2012-July/083984.html, http://lists.fedoraproject.org/pipermail/package-announce/2012-July/083969.html, https://github.com/advisories/GHSA-cm54-3vvf-f5p8
Affected packages
Package
Name: nova
Purl: pkg:pypi/nova
