LWN.net Logo

SUSE alert SUSE-SU-2012:1455-1 (openstack-glance)

From:  opensuse-security@opensuse.org
To:  opensuse-security-announce@opensuse.org
Subject:  [security-announce] SUSE-SU-2012:1455-1: important: Security update for openstack-glance
Date:  Thu, 8 Nov 2012 18:08:45 +0100 (CET)
Message-ID:  <20121108170845.E982F32289@maintenance.suse.de>
Archive-link:  Article, Thread

SUSE Security Update: Security update for openstack-glance ______________________________________________________________________________ Announcement ID: SUSE-SU-2012:1455-1 Rating: important References: #787814 Cross-References: CVE-2012-4573 Affected Products: SUSE Cloud 1.0 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: OpenStack glance had a bug where image deletion was allowed for all logged in users (CVE-2012-4573). This has been fixed. Security Issue reference: * CVE-2012-4573 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4573 > Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Cloud 1.0: zypper in -t patch sleclo10sp2-openstack-glance-7033 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Cloud 1.0 (x86_64): openstack-glance-2012.1+git.1344578005.120fcf4-0.7.1 python-glance-2012.1+git.1344578005.120fcf4-0.7.1 References: http://support.novell.com/security/cve/CVE-2012-4573.html https://bugzilla.novell.com/787814 http://download.novell.com/patch/finder/?keywords=702ffac... -- To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-security-announce+help@opensuse.org


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds