Bug 929535 (CVE-2015-3156) - VUL-1: CVE-2015-3156 openstack-trove: multiple insecure /tmp file usage issues
Summary: VUL-1: CVE-2015-3156 openstack-trove: multiple insecure /tmp file usage issues
Status: RESOLVED FIXED
Alias: CVE-2015-3156
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Assignee: Bernhard Wiedemann
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/116424/
Whiteboard: CVSSv2:RedHat:CVE-2015-3156:3.8:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2015-05-04 13:41 UTC by Sebastian Krahmer
Modified: 2017-08-04 11:34 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Krahmer 2015-05-04 13:41:13 UTC
There are multiple tmp file-access issues in openstack-trove. The severity
is low, as also pointed out by upstream: https://bugs.launchpad.net/trove/+bug/1398195 therefore marking it for pending.


rh#1216073

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1216073
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-3156
http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-3156.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3156
Comment 1 Bernhard Wiedemann 2016-01-04 10:01:51 UTC
added patch to Juno/Cloud5 package
should already be in later versions
Comment 2 Swamp Workflow Management 2016-03-14 14:13:19 UTC
SUSE-SU-2016:0739-1: An update that fixes one vulnerability is now available.

Category: security (low)
Bug References: 929535
CVE References: CVE-2015-3156
Sources used:
SUSE OpenStack Cloud 5 (src):    openstack-trove-2014.2.4.juno-15.1, openstack-trove-doc-2014.2.4.juno-15.1
Comment 3 Johannes Segitz 2017-08-04 11:34:36 UTC
fixed