Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-9684

Overview

Vulnerability Score 4.0 4.0
CVE Id CVE-2014-9684
Last Modified 11 May 2015 10:02:07
Published 24 Feb 2015 10:59:03
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2014-9684

Summary

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them before the uploads finish, a different vulnerability than CVE-2015-1881.

Vulnerable Systems

Application

  • Openstack Image Registry And Delivery Service %28glance%29 2014.2

  • Openstack Image Registry And Delivery Service %28glance%29 2014.2.1

  • Openstack Image Registry And Delivery Service %28glance%29 2014.2.2


References

CONFIRM - https://bugs.launchpad.net/glance/+bug/1371118

MLIST - [openstack-announce] 20150223 [OSSA 2015-004] Glance import task leaks image in backend (CVE-2014-9684, CVE-2015-1881)

REDHAT - RHSA-2015:0938


Last Updated: 27 May 2016 11:08:38