CVE-2014-0134

Publication date 8 May 2014

Last updated 24 July 2024


Ubuntu priority

The instance rescue mode in OpenStack Compute (Nova) 2013.2 before 2013.2.3 and Icehouse before 2014.1, when using libvirt to spawn images and use_cow_images is set to false, allows remote authenticated users to read certain compute host files by overwriting an instance disk with a crafted image.

Read the notes from the security team

Status

Package Ubuntu Release Status
nova 14.04 LTS trusty Not in release
13.10 saucy
Fixed 1:2013.2.3-0ubuntu1.2
12.10 quantal
Not affected
12.04 LTS precise
Not affected
10.04 LTS lucid Not in release

Notes


jdstrand

1:2013.2.3-0ubuntu1 is now in saucy-updates introduced in grizzly

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
nova

References

Related Ubuntu Security Notices (USN)

    • USN-2247-1
    • OpenStack Nova vulnerabilities
    • 17 June 2014

Other references