The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to execute arbitrary commands via a crafted location.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.ubuntu.com/usn/USN-2193-1 | vendor advisory |
https://launchpad.net/bugs/1298698 | |
http://www.openwall.com/lists/oss-security/2014/04/10/13 | mailing list |
http://rhn.redhat.com/errata/RHSA-2014-0455.html | vendor advisory |