CVE-2015-1851
Publication date 25 June 2015
Last updated 24 July 2024
Ubuntu priority
OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
Status
Package | Ubuntu Release | Status |
---|---|---|
cinder | ||
14.04 LTS trusty | Not in release | |
Notes
References
Related Ubuntu Security Notices (USN)
- USN-2703-1
- Cinder vulnerability
- 6 August 2015