Ubuntu Security Update USN-6882-2: Cinder regression

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,844
Reaction score
74
Credits
-1,257
USN-6882-1 fixed vulnerabilities in Cinder. The update caused a regression in certain environments due to incorrect privilege handling. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Martin Kaesberger discovered that Cinder incorrectly handled QCOW2 image processing. An authenticated user could use this issue to access arbitrary files on the server, possibly exposing sensitive information.

Continue reading...
 


Follow Linux.org

Staff online

Members online


Top