|
|
|
|
| |
Credit:
The information has been provided by Gabe Westmaas.
|
| |
Vulnerable Systems:
* LibTIFF 4.0.3
OpenStack Glance could allow a remote attacker to bypass security restrictions, caused by the failure to properly check the registry permissions prior to deleting image files by the backend storage repository. An attacker could exploit this vulnerability to delete image files.
CVE-2012-4573:The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.
CVE-2012-5482:The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.
CVE Information:
CVE-2012-4573
CVE-2012-5482
Disclosure Timeline:
Published: November 08 2012
|
|
|
|
|