Access Restriction Bypass Affecting cinder package, versions <2014.1.1-3
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIAN13-CINDER-5677940
- published 19 Jun 2014
- disclosed 19 Jun 2014
Introduced: 19 Jun 2014
CVE-2013-1068 Open this link in a new tabHow to fix?
Upgrade Debian:13
cinder
to version 2014.1.1-3 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream cinder
package and not the cinder
package as distributed by Debian
.
See How to fix?
for Debian:13
relevant fixed versions and status.
The OpenStack Nova (python-nova) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.2 and 1:2014.1-0 before 1:2014.1-0ubuntu1.2 and Openstack Cinder (python-cinder) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.1 and 1:2014.1-0 before 1:2014.1-0ubuntu1.1 for Ubuntu 13.10 and 14.04 LTS does not properly set the sudo configuration, which makes it easier for attackers to gain privileges by leveraging another vulnerability.