Release date:
Updated on: 2013-02-01
Affected Systems:
Openstack Glance Essex (2012.1)
Openstack Glance Folsom (2012.2)
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57612
CVE (CAN) ID: CVE-2013-0212
OpenStack Glance is an OpenStack graphics service that provides virtual disk image search, registration, and delivery services.
Problems in the error reporting mechanism in Folsom (2012.2) and Essex (2012.1) versions can be recorded in the Swift creden of operators with nonexistent access and misconfiguration, the Swift credential of the operator is disclosed in the error message.
<* Source: Dan Prince
Link: http://secunia.com/advisories/51957/
Http://www.openwall.com/lists/oss-security/2013/01/29/10
Https://bugs.launchpad.net/glance/+bug/1098962
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Openstack
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://lists.openstack.org/pipermail/openstack-announce/