Bug 846197 - (CVE-2013-4428) VUL-0: CVE-2013-4428: openStack-glance: image_download policy not enforced for cached images
(CVE-2013-4428)
VUL-0: CVE-2013-4428: openStack-glance: image_download policy not enforced fo...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
maint:released:sle11-sp3:55536
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2013-10-16 11:46 UTC by Victor Pereira
Modified: 2014-01-21 08:08 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2013-10-16 11:46:26 UTC
CVE-2013-4428

**Only setups making use of the download_image policy are affected.**

Image_download policy could not be enforced for cached images. This could result in disclosure of image contents that
were thought to be protected by the download_image policy setting.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-4428
https://bugzilla.redhat.com/show_bug.cgi?id=1019572
Comment 1 Victor Pereira 2013-10-16 11:47:27 UTC
are we affected?
Comment 2 Swamp Workflow Management 2013-10-16 22:00:20 UTC
bugbot adjusting priority
Comment 3 Vincent Untz 2013-11-21 14:46:07 UTC
Sascha: here are the latest security issues we have.
Comment 4 Sascha Peilicke 2013-12-06 13:34:18 UTC
sr#29812
Comment 5 Swamp Workflow Management 2013-12-17 09:31:29 UTC
The SWAMPID for this issue is 55535.
This issue was rated as moderate.
Please submit fixed packages until 2013-12-31.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 6 Sebastian Krahmer 2014-01-20 15:21:44 UTC
released
Comment 7 Swamp Workflow Management 2014-01-20 17:53:49 UTC
Update released for: openstack-glance, openstack-glance-test, python-glance
Products:
SUSE-CLOUD 2.0 (x86_64)
Comment 8 Swamp Workflow Management 2014-01-20 21:04:23 UTC
SUSE-SU-2014:0102-1: An update that solves one vulnerability and has one errata is now available.

Category: security (moderate)
Bug References: 846197,852600
CVE References: CVE-2013-4428
Sources used:
SUSE Cloud 2.0 (src):    openstack-glance-2013.1.5.a2.gf4aaf8e-0.7.1