Bugzilla – Bug 929535
VUL-1: CVE-2015-3156 openstack-trove: multiple insecure /tmp file usage issues
Last modified: 2017-08-04 11:34:36 UTC
There are multiple tmp file-access issues in openstack-trove. The severity is low, as also pointed out by upstream: https://bugs.launchpad.net/trove/+bug/1398195 therefore marking it for pending. rh#1216073 References: https://bugzilla.redhat.com/show_bug.cgi?id=1216073 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-3156 http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-3156.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3156
added patch to Juno/Cloud5 package should already be in later versions
SUSE-SU-2016:0739-1: An update that fixes one vulnerability is now available. Category: security (low) Bug References: 929535 CVE References: CVE-2015-3156 Sources used: SUSE OpenStack Cloud 5 (src): openstack-trove-2014.2.4.juno-15.1, openstack-trove-doc-2014.2.4.juno-15.1
fixed