Executive Summary
Summary | |
---|---|
Title | Glance vulnerability |
Informations | |||
---|---|---|---|
Name | USN-1626-1 | First vendor Publication | 2012-11-08 |
Vendor | Ubuntu | Last vendor Modification | 2012-11-08 |
Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:S/C:N/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 5.5 | Attack Range | Network |
Cvss Impact Score | 4.9 | Attack Complexity | Low |
Cvss Expoit Score | 8 | Authentication | Requires single instance |
Calculate full CVSS 2.0 Vectors scores |
Detail
A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.10 - Ubuntu 12.04 LTS Summary: Glance could be made to delete arbitrary images. Software Description: - glance: OpenStack Image Registry and Delivery Service Details: Gabe Westmaas discovered that Glance did not always properly enforce access controls when deleting images. An authenticated user could delete arbitrary images by using the v1 API under certain circumstances. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.10: Ubuntu 12.04 LTS: In general, a standard system update will make all the necessary changes. References: Package Information: https://launchpad.net/ubuntu/+source/glance/2012.1.3+stable~20120821-120fcf-0ubuntu1.2 |
Original Source
Url : http://www.ubuntu.com/usn/USN-1626-1 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-264 | Permissions, Privileges, and Access Controls |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:18021 | |||
Oval ID: | oval:org.mitre.oval:def:18021 | ||
Title: | USN-1626-1 -- glance vulnerability | ||
Description: | Glance could be made to delete arbitrary images. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-1626-1 CVE-2012-4573 | Version: | 7 |
Platform(s): | Ubuntu 12.10 Ubuntu 12.04 | Product(s): | glance |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:18027 | |||
Oval ID: | oval:org.mitre.oval:def:18027 | ||
Title: | USN-1626-2 -- glance vulnerability | ||
Description: | Glance could be made to delete arbitrary images. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-1626-2 CVE-2012-4573 | Version: | 7 |
Platform(s): | Ubuntu 12.10 | Product(s): | glance |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 | |
Application | 1 | |
Application | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2012-11-23 | Name : Fedora Update for openstack-glance FEDORA-2012-18085 File : nvt/gb_fedora_2012_18085_openstack-glance_fc17.nasl |
2012-11-15 | Name : Ubuntu Update for glance USN-1626-2 File : nvt/gb_ubuntu_USN_1626_2.nasl |
2012-11-09 | Name : Ubuntu Update for glance USN-1626-1 File : nvt/gb_ubuntu_USN_1626_1.nasl |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2012-11-21 | Name : The remote Fedora host is missing a security update. File : fedora_2012-18085.nasl - Type : ACT_GATHER_INFO |
2012-11-14 | Name : The remote Fedora host is missing a security update. File : fedora_2012-17901.nasl - Type : ACT_GATHER_INFO |
2012-11-12 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-1626-2.nasl - Type : ACT_GATHER_INFO |
2012-11-09 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-1626-1.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 12:01:02 |
|
2012-11-13 13:21:59 |
|
2012-11-11 17:20:41 |
|
2012-11-08 21:18:53 |
|