~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
PublicDateAtUSN: 2012-07-03 15:00:00
Candidate: CVE-2012-3360
CRD: 2012-07-03 15:00:00
PublicDate: 2012-07-22
References: 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3360
 http://www.ubuntu.com/usn/usn-1497-1
Description:
 Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute
 (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based
 hypervisors, allows remote authenticated users to write arbitrary files to
 the disk image via a .. (dot dot) in the path attribute of a file element.
Ubuntu-Description: 
Notes: 
 tyhicks> Per OpenStack Vuln Mgmt Team, only Essex and later are affected
Bugs: 
 https://bugs.launchpad.net/nova/+bug/1015531
Priority: high
Discovered-by: Matthias Weckbecker
Assigned-to: sbeattie

Patches_nova:
upstream_nova: released (2012.2~f2)
hardy_nova: DNE
lucid_nova: DNE
natty_nova: not-affected
oneiric_nova: not-affected (2011.3-0ubuntu6.8)
precise_nova: released (2012.1+stable~20120612-3ee026e-0ubuntu1.1)
devel_nova: not-affected (2012.2~f2-0ubuntu1)