LWN.net Logo

eucalyptus: privilege escalation

Package(s):eucalyptus CVE #(s):CVE-2010-3905
Created:December 17, 2010 Updated:December 22, 2010
Description: From the Ubuntu advisory:

It was discovered that Eucalyptus did not verify password resets from the Admin UI correctly. An unauthenticated remote attacker could issue password reset requests to gain admin privileges in the Eucalyptus environment.

Alerts:
Ubuntu USN-1033-1 2010-12-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds