Bugzilla – Bug 846197
VUL-0: CVE-2013-4428: openStack-glance: image_download policy not enforced for cached images
Last modified: 2014-01-21 08:08:25 UTC
CVE-2013-4428 **Only setups making use of the download_image policy are affected.** Image_download policy could not be enforced for cached images. This could result in disclosure of image contents that were thought to be protected by the download_image policy setting. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-4428 https://bugzilla.redhat.com/show_bug.cgi?id=1019572
are we affected?
bugbot adjusting priority
Sascha: here are the latest security issues we have.
sr#29812
The SWAMPID for this issue is 55535. This issue was rated as moderate. Please submit fixed packages until 2013-12-31. When done, please reassign the bug to security-team@suse.de. Patchinfo will be handled by security team.
released
Update released for: openstack-glance, openstack-glance-test, python-glance Products: SUSE-CLOUD 2.0 (x86_64)
SUSE-SU-2014:0102-1: An update that solves one vulnerability and has one errata is now available. Category: security (moderate) Bug References: 846197,852600 CVE References: CVE-2013-4428 Sources used: SUSE Cloud 2.0 (src): openstack-glance-2013.1.5.a2.gf4aaf8e-0.7.1