Bug 938349 (CVE-2015-3289) - VUL-0: CVE-2015-3289: openstack-glance: Glance task flow may fail to delete image from backend
Summary: VUL-0: CVE-2015-3289: openstack-glance: Glance task flow may fail to delete i...
Status: RESOLVED FIXED
Alias: CVE-2015-3289
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 13.2
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Cloud Bugs
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-07-16 09:25 UTC by Andreas Stieger
Modified: 2015-10-01 13:22 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2015-07-16 09:25:26 UTC
EMBARGOED
CRD: 2015-07-28 15:00UTC

This is an advance warning of a vulnerability discovered in OpenStack,
to give you, as downstream stakeholders, a chance to coordinate the
release of fixes and reduce the vulnerability window. Please treat the
following information as confidential until the proposed public
disclosure date.

Title: Glance task flow may fail to delete image from backend
Reporter: Abhishek Kekane (NTT)
Products: Glance
Affects: 2015.1.0

Description:
Abhishek Kekane from NTT reported a vulnerability in Glance. By creating
numerous images using the import task flow API and deleting them, an
authenticated attacker may accumulate untracked image data in the
backend resulting in potential resource exhaustion and denial of
service. All glance setups are affected.

Proposed fix:
Fixes for this vulnerability have already been merged via these reviews:
    master  - https://review.openstack.org/#/c/181345/
    kilo    - https://review.openstack.org/#/c/181816/

CVE: CVE-2015-3289

Proposed public disclosure date/time:
2015-07-28, 1500UTC
Please do not make this issue public before the coordinated embargo
date.

Regards,

--
Grant Murphy
OpenStack Vulnerability Management Team



References:
https://bugs.launchpad.net/glance/+bug/1453068
https://review.openstack.org/#/c/181345/
https://review.openstack.org/#/c/181816/
Comment 1 Swamp Workflow Management 2015-07-16 21:59:51 UTC
bugbot adjusting priority
Comment 2 Andreas Stieger 2015-07-17 11:06:18 UTC
By version and glancing at the code. I see SLE / Cloud not affected, making this an openSUSE bug. Dear maintainer if you know otherwise let me know.

Please note the embargo, do not build on OBS until it is lifted.
Comment 3 Johannes Segitz 2015-07-28 15:37:47 UTC
public, please submit for openSUSE
Comment 4 Andreas Stieger 2015-10-01 13:22:59 UTC
I wonder if any one is actually reading cloud-bugs@suse.de

Fixed now in OBS:
Cloud:OpenStack:Master/openstack-glance
Cloud:OpenStack:Liberty/openstack-glance
Cloud:OpenStack:Kilo/openstack-glance
Cloud:OpenStack:Kilo:Staging/openstack-glance