PublicDateAtUSN: 2015-09-22 15:00:00 Candidate: CVE-2015-5251 CRD: 2015-09-22 15:00:00 PublicDate: 2015-10-26 17:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5251 http://lists.openstack.org/pipermail/openstack-announce/2015-September/000655.html https://ubuntu.com/security/notices/USN-3446-1 Description: OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/*. Ubuntu-Description: Notes: tyhicks> 12.04 likely needs the ACTIVE_IMMUTABLE check, as well. Bugs: https://bugs.launchpad.net/bugs/1482371 Priority: low Discovered-by: Hemanth Makkapati Assigned-to: mdeslaur CVSS: Patches_glance: upstream: https://review.openstack.org/226338 (juno) upstream: https://review.openstack.org/226337 (Kilo) upstream: https://review.openstack.org/226336 (Liberty) vendor: vendor: http://ftp.redhat.com/pub/redhat/linux/enterprise/7Server/en/RHOS/SRPMS/openstack-glance-2014.1.5-5.el7ost.src.rpm upstream_glance: needed precise_glance: ignored (reached end-of-life) precise/esm_glance: DNE (precise was needed) trusty_glance: released (1:2014.1.5-0ubuntu1.1) trusty/esm_glance: DNE (trusty was released [1:2014.1.5-0ubuntu1.1]) vivid_glance: not-affected (1:2015.1.2-0ubuntu1) vivid/stable-phone-overlay_glance: DNE vivid/ubuntu-core_glance: DNE wily_glance: not-affected (2:11.0.0-0ubuntu1) xenial_glance: not-affected (2:11.0.0-0ubuntu1) esm-infra/xenial_glance: not-affected (2:11.0.0-0ubuntu1) yakkety_glance: not-affected (2:11.0.0-0ubuntu1) zesty_glance: not-affected (2:11.0.0-0ubuntu1) devel_glance: not-affected (2:11.0.0-0ubuntu1)