CVE-2013-1068
Ubuntu Linux OpenStack Nova and Cinder - Privilege Escalation via Improper Sudo Configuration
Title source: llmDescription
The OpenStack Nova (python-nova) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.2 and 1:2014.1-0 before 1:2014.1-0ubuntu1.2 and Openstack Cinder (python-cinder) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.1 and 1:2014.1-0 before 1:2014.1-0ubuntu1.1 for Ubuntu 13.10 and 14.04 LTS does not properly set the sudo configuration, which makes it easier for attackers to gain privileges by leveraging another vulnerability.
References (2)
Core 2
Core References
Patch, Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://ubuntu.com/usn/usn-2248-1
Patch, Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2247-1
Scores
EPSS
0.0119
EPSS Percentile
64.6%
Details
CWE
CWE-264
Status
published
Products (2)
canonical/ubuntu_linux
13.10
canonical/ubuntu_linux
14.04
Published
Jun 19, 2014
Tracked Since
Feb 18, 2026