Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2015-1881

Overview

Vulnerability Score 4.0 4.0
CVE Id CVE-2015-1881
Last Modified 11 May 2015 10:03:42
Published 24 Feb 2015 10:59:08
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2015-1881

Summary

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them, a different vulnerability than CVE-2014-9684.

Vulnerable Systems

Application

  • Openstack Image Registry And Delivery Service %28glance%29 2014.2

  • Openstack Image Registry And Delivery Service %28glance%29 2014.2.1

  • Openstack Image Registry And Delivery Service %28glance%29 2014.2.2


References

CONFIRM - https://bugs.launchpad.net/glance/+bug/1420696

MLIST - [openstack-announce] 20150223 [OSSA 2015-004] Glance import task leaks image in backend (CVE-2014-9684, CVE-2015-1881)

REDHAT - RHSA-2015:0938


Last Updated: 27 May 2016 11:07:56