Candidate: CVE-2014-9623 PublicDate: 2015-01-23 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9623 http://lists.openstack.org/pipermail/openstack-announce/2015-January/000327.html Description: OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state. Ubuntu-Description: Notes: Bugs: https://launchpad.net/bugs/1398830 Priority: medium Discovered-by: Tushar Patil Assigned-to: mdeslaur CVSS: Patches_glance: upstream: https://review.openstack.org/149646 (icehouse) upstream: https://review.openstack.org/149387 (juno) upstream: https://review.openstack.org/144464 (kilo) upstream_glance: needs-triage lucid_glance: DNE precise_glance: not-affected (code not present) trusty_glance: released (1:2014.1.4-0ubuntu1) trusty/esm_glance: DNE (trusty was released [1:2014.1.4-0ubuntu1]) utopic_glance: not-affected (1:2014.2.2-0ubuntu1) vivid_glance: not-affected (1:2015.1~b2-0ubuntu1) devel_glance: not-affected (1:2015.1~b2-0ubuntu1)