=========================================================================Ubuntu Security Notice USN-2325-1
August 21, 2014

nova vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS

Summary:

OpenStack Nova could be made to expose sensitive information over the
network.

Software Description:
- nova: OpenStack Compute cloud infrastructure

Details:

Alex Gaynor discovered that OpenStack Nova would sometimes respond with
variable times when comparing authentication tokens. If nova were
configured to proxy metadata requests via Neutron, a remote authenticated
attacker could exploit this to conduct timing attacks and ascertain
configuration details of another instance.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
  python-nova                     1:2014.1.2-0ubuntu1.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2325-1
  CVE-2014-3517

Package Information:
  https://launchpad.net/ubuntu/+source/nova/1:2014.1.2-0ubuntu1.1




Ubuntu 2325-1: OpenStack Nova vulnerability

August 21, 2014
OpenStack Nova could be made to expose sensitive information over the network.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: python-nova 1:2014.1.2-0ubuntu1.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2325-1

CVE-2014-3517

Severity
=========================================================================Ubuntu Security Notice USN-2325-1

Package Information

https://launchpad.net/ubuntu/+source/nova/1:2014.1.2-0ubuntu1.1

Related News