CVE-2015-1851
Canonical Ubuntu Linux < 2014.1.4 - Information Disclosure
Title source: ruleDescription
OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
References (8)
Core 8
Core References
Vendor Advisory mailing-list
x_refsource_mlist
http://lists.openstack.org/pipermail/openstack-announce/2015-June/000367.html
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2015/dsa-3292
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/06/13/1
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/06/17/7
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-1206.html
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2703-1
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/06/17/2
Issue Tracking x_refsource_confirm
https://bugs.launchpad.net/cinder/+bug/1415087
Scores
EPSS
0.0051
EPSS Percentile
66.6%
Details
CWE
CWE-200
Status
published
Products (7)
canonical/ubuntu_linux
15.04
openstack/icehouse
< 2014.1.4
openstack/juno
2014.2
openstack/juno
2014.2.2
openstack/juno
2014.2.3
openstack/kilo
2015.1.0
pypi/cinder
0 - 7.0.0a0PyPI
Published
Jun 25, 2015
Tracked Since
Feb 18, 2026