Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.843336
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-3451-1)
Summary:The remote host is missing an update for the 'swift' package(s) announced via the USN-3451-1 advisory.
Description:Summary:
The remote host is missing an update for the 'swift' package(s) announced via the USN-3451-1 advisory.

Vulnerability Insight:
It was discovered that OpenStack Swift incorrectly handled tempurls. A
remote authenticated user in possession of a tempurl key authorized for PUT
could retrieve other objects in the same Swift account. (CVE-2015-5223)

Romain Le Disez and Orjan Persson discovered that OpenStack Swift
incorrectly closed client connections. A remote attacker could possibly use
this issue to consume resources, resulting in a denial of service.
(CVE-2016-0737, CVE-2016-0738)

Affected Software/OS:
'swift' package(s) on Ubuntu 14.04.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2015-5223
84827
http://www.securityfocus.com/bid/84827
RHSA-2015:1895
http://rhn.redhat.com/errata/RHSA-2015-1895.html
RHSA-2016:0329
http://rhn.redhat.com/errata/RHSA-2016-0329.html
SUSE-SU-2015:1846
http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00025.html
[oss-security] 20150826 Subject: [OSSA 2015-016] Information leak via Swift tempurls (CVE-2015-5223)
http://www.openwall.com/lists/oss-security/2015/08/26/5
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
https://bugs.launchpad.net/swift/+bug/1449212
https://bugs.launchpad.net/swift/+bug/1453948
https://security.openstack.org/ossa/OSSA-2015-016.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-0737
81432
http://www.securityfocus.com/bid/81432
RHSA-2016:0128
http://rhn.redhat.com/errata/RHSA-2016-0128.html
RHSA-2016:0155
http://rhn.redhat.com/errata/RHSA-2016-0155.html
https://bugs.launchpad.net/swift/+bug/1466549
https://launchpad.net/swift/+milestone/2.4.0
https://review.openstack.org/#/c/217750/
https://security.openstack.org/ossa/OSSA-2016-004.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-0738
FEDORA-2016-2256c80a94
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176713.html
https://bugs.launchpad.net/cloud-archive/+bug/1493303
https://github.com/openstack/swift/blob/master/CHANGELOG
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.