Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 566088 - <app-admin/glance-12.0.0: Use of MD5 in OpenStack Glance image signature
Summary: <app-admin/glance-12.0.0: Use of MD5 in OpenStack Glance image signature
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-11-17 22:06 UTC by Kristian Fiskerstrand (RETIRED)
Modified: 2016-10-15 23:17 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Kristian Fiskerstrand (RETIRED) gentoo-dev 2015-11-17 22:06:22 UTC
From ${URL}:
A vulnerability was discovered in OpenStack (see below). In order to
ensure full traceability, we need a CVE number assigned that we can
attach to further notifications. This issue is already public, although
an advisory was not sent yet.

Title: Use of MD5 in OpenStack Glance image signature
Reporter: Daniel P. Berrange (Red Hat)
Products: Glance
Affects: =11.0.0

Description:
Daniel P. Berrange from Red Hat reported a vulnerability in Glance image
signature. Glance computes cryptographic signature using MD5 hash of the
image. By crafting a malicious image that produces a MD5 collision, a
Glance backend operator may subvert the signature verification process,
resulting in a corrupted image. All Glance setups are affected.

References:
https://launchpad.net/bugs/1516031

Thanks in advance,

--
Tristan Cacqueray
OpenStack Vulnerability Management Team
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2016-07-19 10:52:00 UTC
The patch from upstream is present in 12.0.0, but is not in 11.0.1.  Please clean the tree of 11.0.1-r1 as 12.0.0 is already stable.

Upstream commit:

https://git.openstack.org/cgit/openstack/glance/commit/?id=09a0acefc7d27b85e7145611a3852bcf0765f769
Comment 2 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2016-10-15 17:28:15 UTC
cleaned up a while ago and forgot to mention it here

cleaned up, removing self from cc
Comment 3 Aaron Bauman (RETIRED) gentoo-dev 2016-10-15 23:17:49 UTC
GLSA Vote: No