LWN.net Logo

openstack-packstack: multiple vulnerabilities

Package(s):openstack-packstack CVE #(s):CVE-2013-0261 CVE-2013-0266
Created:March 6, 2013 Updated:March 6, 2013
Description: From the Red Hat advisory:

A flaw was found in PackStack. During manifest creation, the manifest file was written to /tmp/ with a predictable file name. A local attacker could use this flaw to perform a symbolic link attack, overwriting an arbitrary file accessible to the user running PackStack with the contents of the manifest, which could lead to a denial of service. Additionally, the attacker could read and potentially modify the manifest being generated, allowing them to modify systems being deployed using OpenStack. (CVE-2013-0261)

It was discovered that the cinder.conf and all api-paste.ini configuration files were created with world-readable permissions. A local attacker could use this flaw to view administrative passwords, allowing them to control systems deployed and managed by OpenStack. (CVE-2013-0266)

Alerts:
Red Hat RHSA-2013:0595-01 2013-03-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds