Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 496774 (CVE-2013-6480) - <dev-python/libcloud-0.14.1 : Information disclosure (CVE-2013-6480)
Summary: <dev-python/libcloud-0.14.1 : Information disclosure (CVE-2013-6480)
Status: RESOLVED FIXED
Alias: CVE-2013-6480
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-01-02 14:45 UTC by Agostino Sarubbo
Modified: 2014-05-28 09:33 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-01-02 14:45:47 UTC
From ${URL} :

DigitalOcean recently changed the default API behavior from scrub to non-scrub when destroying a VM.

Libcloud doesn't explicitly send "scrub_data" query parameter when destroying a node. This means nodes 
which are destroyed using Libcloud are vulnerable to later customers stealing data contained on them. Only 
users who are using DigitalOcean driver are known to be affected by this issue.

The issue is said to be fixed in the version 0.13.3.

References:
http://seclists.org/fulldisclosure/2014/Jan/11
http://libcloud.apache.org/security.html
https://digitalocean.com/blog_posts/transparency-regarding-data-security
https://github.com/fog/fog/issues/2525

Commit:
https://github.com/apache/libcloud/commit/4449e165a00756dc61430e6ad9520f005b045d29


@maintainer(s): since the package has never been marked as stable, we don't need to stabilize it. After the bump, please remove the affected versions from the tree.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2014-01-11 17:51:04 UTC
CVE-2013-6480 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6480):
  Libcloud 012.3 through 0.13.2 does not set the scrub_data parameter for the
  destroy DigitalOcean API, which allows local users to obtain sensitive
  information by leveraging a new VM.
Comment 2 Patrick McLean gentoo-dev 2014-02-26 23:16:27 UTC
libcloud-0.14.1 is now in the tree
Comment 3 Sergey Popov gentoo-dev 2014-04-28 12:49:17 UTC
(In reply to Patrick McLean from comment #2)
> libcloud-0.14.1 is now in the tree

Thanks, no stable version in tree, thus - noglsa. Please, remove vulnerable versions from tree
Comment 4 Yury German Gentoo Infrastructure gentoo-dev 2014-05-21 03:50:52 UTC
Vulnerable versions still in tree... 

Maintainer(s), please drop the vulnerable version.
Comment 5 Dirkjan Ochtman (RETIRED) gentoo-dev 2014-05-28 07:28:32 UTC
Done. Sorry it took so long.