Bug 779215 (CVE-2012-4406) - VUL-0: CVE-2012-4406: openstack-swift: code execution by deserialization
Summary: VUL-0: CVE-2012-4406: openstack-swift: code execution by deserialization
Status: RESOLVED FIXED
Alias: CVE-2012-4406
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:released:sle11-sp2:49232
Keywords:
Depends on:
Blocks:
 
Reported: 2012-09-07 09:46 UTC by Marcus Meissner
Modified: 2013-08-16 11:55 UTC (History)
4 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2012-09-07 09:46:29 UTC
is public, via oss-sec

CVE-2012-4406

Subject: [oss-security] CVE-Request: openstack pickle de-serialization
From: Sebastian Krahmer <krahmer@suse.de>

Hi,

During openstack review we found that some parts of openstack
used pickle to de-serialize data. This could be used to execute
arbitrary code. Please check here:

https://bugs.launchpad.net/swift/+bug/1006414

Can someone please assign a CVE, for completeness?

thx,
Sebastian
Comment 1 Vincent Untz 2012-09-07 12:23:46 UTC
My fix for this was reviewed only recently, so we didn't have the fix in our packages.

It's easy to push the fix now that it's public, though. Where do you want me to submit it?
Comment 3 Swamp Workflow Management 2012-09-07 22:00:28 UTC
bugbot adjusting priority
Comment 4 Vincent Untz 2012-09-10 08:10:27 UTC
I've committed the fix to Devel:Cloud. Before we push this as a security update, I'd like to see some jenkins run with the patch.

For Factory, I've submitted sr#133427.

For 12.2... The patch doesn't apply cleanly. It's low priority for me right now, so I might take a look later.
Comment 5 Vincent Untz 2012-09-10 10:22:29 UTC
(In reply to comment #4)
> I've committed the fix to Devel:Cloud. Before we push this as a security
> update, I'd like to see some jenkins run with the patch.

Submitted to SUSE:SLE-11-SP2:Update:Test: sr#21677.

We're discussing inside the team how the openstack packages are maintained for openSUSE. So not sure if we'll release a 12.2 update right now.

(Note that the bug is actually not too critical -- a proper openstack deployment would have that part of swift isolated on a different network)
Comment 11 Christoph Thiel 2012-09-13 10:37:14 UTC
Sounds good to me. Closing this bug fixed, as the package has been checked in. swamp process running.
Comment 12 Swamp Workflow Management 2012-10-16 17:48:13 UTC
Update released for: openstack-swift, openstack-swift-account, openstack-swift-container, openstack-swift-doc, openstack-swift-object, openstack-swift-proxy, openstack-swift-test, python-swift
Products:
SUSE-CLOUD 1.0 (x86_64)