UBUNTU-CVE-2013-1068
Dashboard / Vulnerabilities / UBUNTU-CVE-2013-1068
UBUNTU-CVE-2013-1068
Summary:
Details: The OpenStack Nova (python-nova) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.2 and 1:2014.1-0 before 1:2014.1-0ubuntu1.2 and Openstack Cinder (python-cinder) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.1 and 1:2014.1-0 before 1:2014.1-0ubuntu1.1 for Ubuntu 13.10 and 14.04 LTS does not properly set the sudo configuration, which makes it easier for attackers to gain privileges by leveraging another vulnerability.
References: https://ubuntu.com/security/CVE-2013-1068, https://wiki.openstack.org/wiki/Packager/Rootwrap, https://ubuntu.com/security/notices/USN-2247-1, https://ubuntu.com/security/notices/USN-2248-1, https://www.cve.org/CVERecord?id=CVE-2013-1068
Affected packages
Package
Name: cinder
Purl: pkg:deb/ubuntu/cinder@1:2014.1-0ubuntu1.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
