Bug 1026171 (CVE-2013-4497)
Summary: | CVE-2013-4497 openstack-nova: XenAPI security groups not kept through migrate or resize | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | [Other] Security Response | Reporter: | Garth Mollett <gmollett> | ||||||
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||||
Status: | CLOSED ERRATA | QA Contact: | |||||||
Severity: | low | Docs Contact: | |||||||
Priority: | low | ||||||||
Version: | unspecified | CC: | akscram, alexander.sakhnov, aortega, apevec, apevec, ayoung, bfilippov, breu, chrisw, gkotton, gmollett, iheim, itamar, Jan.van.Eldik, jonathansteffan, jose.castro.leon, lhh, lpeer, markmc, mlvov, mmagr, ndipanov, p, rbryant, rhos-maint, sclewis, sdake, yeylon | ||||||
Target Milestone: | --- | Keywords: | Security | ||||||
Target Release: | --- | ||||||||
Hardware: | All | ||||||||
OS: | Linux | ||||||||
Whiteboard: | |||||||||
Fixed In Version: | Doc Type: | Bug Fix | |||||||
Doc Text: | Story Points: | --- | |||||||
Clone Of: | Environment: | ||||||||
Last Closed: | 2014-07-15 07:13:48 UTC | Type: | --- | ||||||
Regression: | --- | Mount Type: | --- | ||||||
Documentation: | --- | CRM: | |||||||
Verified Versions: | Category: | --- | |||||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
Cloudforms Team: | --- | Target Upstream Version: | |||||||
Embargoed: | |||||||||
Bug Depends On: | 1026172, 1026174, 1026175, 1032286 | ||||||||
Bug Blocks: | 1023240, 1026177 | ||||||||
Attachments: |
|
Description
Garth Mollett
2013-11-04 06:06:18 UTC
Created openstack-nova tracking bugs for this issue: Affects: fedora-all [bug 1026175] External References: https://launchpad.net/bugs/1073306 https://launchpad.net/bugs/1202266 Upstream fixes: https://review.openstack.org/52987 https://review.openstack.org/52991 Created attachment 823795 [details]
cve-2013-4497-stable-grizzly-a.patch
Created attachment 823796 [details]
cve-2013-4497-stable-grizzly-b.patch
We explicitly don't support this functionality but we do provide it, I think fixing it in the next z stream release would be fine. openstack-nova-2013.2.1-2.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report. openstack-nova-2013.1.5-1.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report. This issue has been addressed in following products: OpenStack 3 for RHEL 6 Via RHSA-2014:0366 https://rhn.redhat.com/errata/RHSA-2014-0366.html |