Thierry Carrez <thierry> reports:
Title: Arbitrary file injection/corruption through directory
traversal issues Impact: Critical Reporter: Matthias Weckbecker
(SUSE Security team)
Description: Matthias Weckbecker from SUSE Security team reported a
vulnerability in Nova compute nodes handling of file injection in
disk images. By requesting files to be injected in malicious paths,
a remote authenticated user could inject files in arbitrary
locations on the host file system, potentially resulting in full
compromise of the compute node. Only Essex and later setups running
the OpenStack API over libvirt-based hypervisors are affected.