Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.841210
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-1626-1)
Summary:The remote host is missing an update for the 'glance' package(s) announced via the USN-1626-1 advisory.
Description:Summary:
The remote host is missing an update for the 'glance' package(s) announced via the USN-1626-1 advisory.

Vulnerability Insight:
Gabe Westmaas discovered that Glance did not always properly enforce access
controls when deleting images. An authenticated user could delete arbitrary
images by using the v1 API under certain circumstances.

Affected Software/OS:
'glance' package(s) on Ubuntu 12.04, Ubuntu 12.10.

Solution:
Please install the updated package(s).

CVSS Score:
5.5

CVSS Vector:
AV:N/AC:L/Au:S/C:N/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-4573
51174
http://secunia.com/advisories/51174
51234
http://secunia.com/advisories/51234
56437
http://www.securityfocus.com/bid/56437
87248
http://osvdb.org/87248
FEDORA-2012-17901
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092192.html
RHSA-2012:1558
http://rhn.redhat.com/errata/RHSA-2012-1558.html
SUSE-SU-2012:1455
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00002.html
USN-1626-1
http://www.ubuntu.com/usn/USN-1626-1
USN-1626-2
http://www.ubuntu.com/usn/USN-1626-2
[oss-security] 20121107 [OSSA 2012-017] Authentication bypass for image deletion (CVE-2012-4573)
http://www.openwall.com/lists/oss-security/2012/11/07/6
[oss-security] 20121109 [OSSA 2012-017.1] Authentication bypass for image deletion (CVE-2012-4573, CVE-2012-5482) ERRATA 1
http://www.openwall.com/lists/oss-security/2012/11/09/5
http://packetstormsecurity.com/files/118733/Red-Hat-Security-Advisory-2012-1558-01.html
https://bugs.launchpad.net/glance/+bug/1065187
https://github.com/openstack/glance/commit/6ab0992e5472ae3f9bef0d2ced41030655d9d2bc
https://github.com/openstack/glance/commit/90bcdc5a89e350a358cf320a03f5afe99795f6f6
https://github.com/openstack/glance/commit/efd7e75b1f419a52c7103c7840e24af8e5deb29d
openstack-glance-sec-bypass(79895)
https://exchange.xforce.ibmcloud.com/vulnerabilities/79895
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.