Bug 1085163 (CVE-2014-0162)

Summary: CVE-2014-0162 openstack-glance: remote code execution in Glance Sheepdog backend
Product: [Other] Security Response Reporter: Murray McAllister <mmcallis>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: abaron, aortega, apevec, ayoung, chrisw, eglynn, fpercoco, gkotton, gmollett, jrusnack, lhh, markmc, rbryant, sclewis, security-response-team, sgotliv, vdanen, yeylon
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-11-06 05:41:45 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1085192, 1085193, 1086721, 1086722    
Bug Blocks: 1085165    

Description Murray McAllister 2014-04-08 03:09:32 UTC
A flaw was found in the Glance Sheepdog backend. A user who is able to insert or modify Glance image metadata could use this flaw to execute arbitrary commands with the privileges of the user who is running the Glance service.

Versions 2013.2 up to 2013.2.3 are affected.

Acknowledgements:

Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Paul McMillan (Nebula) as the original reporter.

Comment 6 Murray McAllister 2014-04-11 11:34:23 UTC
Public now:

http://www.openwall.com/lists/oss-security/2014/04/10/13
https://launchpad.net/bugs/1298698

Juno (development branch) fix:
https://review.openstack.org/86622

Icehouse (milestone-proposed branch) fix:
https://review.openstack.org/86625

Havana fix:
https://review.openstack.org/86626

Comment 8 Murray McAllister 2014-04-11 11:35:52 UTC
Created openstack-glance tracking bugs for this issue:

Affects: fedora-20 [bug 1086721]

Comment 9 errata-xmlrpc 2014-04-30 19:06:15 UTC
This issue has been addressed in following products:

  OpenStack 4 for RHEL 6

Via RHSA-2014:0455 https://rhn.redhat.com/errata/RHSA-2014-0455.html

Comment 10 Fedora Update System 2014-05-13 05:03:26 UTC
openstack-glance-2013.2.3-3.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.