Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 573844 (CVE-2016-0757) - <app-admin/glance-11.0.1-r1: image status manipulation through locations removal
Summary: <app-admin/glance-11.0.1-r1: image status manipulation through locations removal
Status: RESOLVED FIXED
Alias: CVE-2016-0757
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2016-02-04 16:56 UTC by Agostino Sarubbo
Modified: 2016-06-13 09:49 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2016-02-04 16:56:48 UTC
From ${URL} :

=================================================================
OSSA-2016-006: Glance image status manipulation through locations
               removal
=================================================================

:Date: February 03, 2016
:CVE: CVE-2016-0757


Affects
~~~~~~
- Glance: <=2015.1.2, >=11.0.0 <= 11.0.1


Description
~~~~~~~~~~
Erno Kuvaja from HPE reported a vulnerability in Glance. By removing
the last location of an image, an authenticated user may change the
image status back to queued and may be able to upload new image data
resulting in a broken Glance's immutability promise. A malicious
tenant may exploit this flaw to silently replace image data it owns,
regardless of the original creator or the visibility settings. Only
setups with show_multiple_locations enabled (not default) are
affected.


Patches
~~~~~~
- https://review.openstack.org/275735 (Kilo)
- https://review.openstack.org/275736 (Liberty)
- https://review.openstack.org/275737 (Mitaka)


Credits
~~~~~~
- Erno Kuvaja from HPE (CVE-2016-0757)


References
~~~~~~~~~
- https://bugs.launchpad.net/bugs/1525915
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0757


Notes
~~~~
- This fix will be included in future 2015.1.3 (kilo) and 11.0.2
  (liberty) releases.
- The proposed fix prevents the removal of the last location of an
  image so that an active image is always available. This action was
  previously incorrectly allowed and the fix might break some users who
  are relying on the false assumption that it would be ok to replace
  the data of existing image in the special case that the multiple
  locations has been configured.


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2016-02-04 17:34:29 UTC
fixed in the following, arches please stablize, allarches

=app-admin/glance-11.0.1-r1
Comment 2 Agostino Sarubbo gentoo-dev 2016-02-05 08:38:31 UTC
amd64 stable
Comment 3 Agostino Sarubbo gentoo-dev 2016-02-05 08:38:59 UTC
x86 stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 4 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2016-02-05 16:28:03 UTC
cleaned up, removing us from cc
Comment 5 Kristian Fiskerstrand (RETIRED) gentoo-dev 2016-02-08 20:21:55 UTC
GLSA Vote: No