USN-3446-1
Dashboard / Vulnerabilities / USN-3446-1
USN-3446-1
Summary: glance vulnerabilities
Details: Hemanth Makkapati discovered that OpenStack Glance incorrectly handled access restrictions. A remote authenticated user could use this issue to change the status of images, contrary to access restrictions. (CVE-2015-5251) Mike Fedosin and Alexei Galkin discovered that OpenStack Glance incorrectly handled the storage quota. A remote authenticated user could use this issue to consume disk resources, leading to a denial of service. (CVE-2015-5286) Erno Kuvaja discovered that OpenStack Glance incorrectly handled the show_multiple_locations option. When show_multiple_locations is enabled, a remote authenticated user could change an image status and upload new image data. (CVE-2016-0757)
References: https://ubuntu.com/security/notices/USN-3446-1, https://ubuntu.com/security/CVE-2015-5251, https://ubuntu.com/security/CVE-2015-5286, https://ubuntu.com/security/CVE-2016-0757
Affected packages
Package
Name: glance
Purl: pkg:deb/ubuntu/glance@1:2014.1.5-0ubuntu1.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
