Summary: | <app-admin/glance-2014.1.2: Glance store DoS through disk space exhaustion (OSSA 2014-028) (CVE-2014-5356) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Kristian Fiskerstrand (RETIRED) <k_f> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | trivial | ||
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://seclists.org/oss-sec/2014/q3/410 | ||
Whiteboard: | ~3 [noglsa] | ||
Package list: | Runtime testing required: | --- |
Description
Kristian Fiskerstrand (RETIRED)
![]() fixed in =app-admin/glance-2014.1.2 vulnerable removed from tree Thanks for the ebuild and cleanup. No stable versions, closing noglsa. CVE-2014-5356 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-5356): OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image. |