CVE-2015-1851

Canonical Ubuntu Linux < 2014.1.4 - Information Disclosure

Title source: rule
STIX 2.1

Description

OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.

References (8)

Core 8
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3292
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/06/13/1
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/06/17/7
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-1206.html
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2703-1
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/06/17/2
Issue Tracking x_refsource_confirm
https://bugs.launchpad.net/cinder/+bug/1415087

Scores

EPSS 0.0051
EPSS Percentile 66.6%

Details

CWE
CWE-200
Status published
Products (7)
canonical/ubuntu_linux 15.04
openstack/icehouse < 2014.1.4
openstack/juno 2014.2
openstack/juno 2014.2.2
openstack/juno 2014.2.3
openstack/kilo 2015.1.0
pypi/cinder 0 - 7.0.0a0PyPI
Published Jun 25, 2015
Tracked Since Feb 18, 2026