-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with undefined - http://www.enigmail.net/
iQIcBAEBCgAGBQJRCFnZAAoJEFHb3FjMVZVz9+EQAIF4a2hfYvnSX0Z8pRYVWRDl
yBDp2mG8E05O3CK8daxKTKg+1tmrMm/gMx8BBRtc/6PFNqD20dWTqPp1HtNFUNvW
sZjFETbNAfhWRD23jt2fOXF3Gev5Etnz1GxUcoakNhnAPBpZrZfLNwnuL3ZEmTlj
CeU1G8FxQ/mWO4ZFAm/iZK9+XrXm1VPBcFqt8aGCfLVYjh6ZspyJLZ+VPY0le010
vStnNCswH4CogRXgCi/vu9uzijrlzk2ATDbN73zrNYzhwIjaoCGex45Ho3j4yTcq
89uc4qpNlu3yAIL5j8J/ruUnq2HN3SP9dHJw8xMcGeQFb7RWsKpuKW+mW9drxk0K
3DcHTJUr/dU4EYz8GkarvMiOqwTBdng+ADuRinV0OXcp3aCS0jxAAxXlCA4A2VYt
3lwL+xmTanSh2SfikEtwfMGP/epORawbN3567gfYmZmE+Z/QdaBo3Ri80xrTM9Y0
/B2ZPX0uBfJL14hRwexU5TeIAdpWaN2JuSJ6X/WJJFASue5oSy0gXbw2SaiyWkgD
Tl3Nh5iXaEnV3c3sjjctmqXYG4mxyc4vjhtp4o+T/FFkEbJjcvVY/WNsn5Smni8a
wEizUd07pd227rK1F/zr2Pf/phbCtJxRPeNziOKgQRvDrSp9eoI+OwqbHKxDYAY1
hPlmt48VVUYrnqAXlsSU
=05hF
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1709-1
January 29, 2013
nova vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.10
- Ubuntu 12.04 LTS
- Ubuntu 11.10
Summary:
Nova volume could be made to expose volumes from other users.
Software Description:
- nova: OpenStack Compute cloud infrastructure
Details:
Phil Day discovered that nova-volume did not validate access to volumes. An
authenticated attacker could exploit this to bypass intended access
controls and boot from arbitrary volumes.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.10:
nova-volume
2012.2.1+stable-20121212-a99a802e-0ubuntu1.1
python-nova
2012.2.1+stable-20121212-a99a802e-0ubuntu1.1
Ubuntu 12.04 LTS:
nova-volume
2012.1.3+stable-20120827-4d2a4afe-0ubuntu1.1
python-nova
2012.1.3+stable-20120827-4d2a4afe-0ubuntu1.1
Ubuntu 11.10:
nova-volume 2011.3-0ubuntu6.11
python-nova 2011.3-0ubuntu6.11
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-1709-1
CVE-2013-0208
Package Information:
https://launchpad.net/ubuntu/+source/nova/2012.2.1+stable-20121212-a99a802e-0ubuntu1.1
https://launchpad.net/ubuntu/+source/nova/2012.1.3+stable-20120827-4d2a4afe-0ubuntu1.1
https://launchpad.net/ubuntu/+source/nova/2011.3-0ubuntu6.11
No comments:
Post a Comment