Format-guessing and file disclosure in image convert (CVE-2015-1850)
Bug #1465333 reported by
Ivan Kolodyazhny
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Mirantis OpenStack |
Fix Released
|
Critical
|
Timur Nurlygayanov | ||
5.1.x |
Fix Released
|
Critical
|
Denis Puchkin | ||
6.0.x |
Fix Released
|
Critical
|
Denis Meltsaykin |
Bug Description
Cinder does not provide input format to several calls of "qemu-img convert". This allows the attacker to play the format guessing by providing a volume with a qcow2 signature. If this signature contains a base file, this file will be read by a process running as root and embedded in the output. This bug is similar to CVE-2013-1922.
Upstream bug: https:/
tags: | added: cinder |
Changed in mos: | |
milestone: | none → 6.1 |
Changed in mos: | |
status: | New → Fix Committed |
importance: | Undecided → High |
Changed in mos: | |
importance: | High → Critical |
information type: | Private Security → Public Security |
Changed in mos: | |
assignee: | Ivan Kolodyazhny (e0ne) → Timur Nurlygayanov (tnurlygayanov) |
tags: | added: feature-security |
To post a comment you must log in.
The fix for stable/juno is merged in upstream so I am nominating it for 6.0-updates and including into MU4.