CVE-2012-4573
Publication date 7 November 2012
Last updated 24 July 2024
Ubuntu priority
The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.
Status
Package | Ubuntu Release | Status |
---|---|---|
glance | 12.10 quantal |
Fixed 2012.2-0ubuntu2.3
|
12.04 LTS precise |
Fixed 2012.1.3+stable~20120821-120fcf-0ubuntu1.2
|
|
11.10 oneiric |
Not affected
|
|
11.04 natty | Ignored end of life | |
10.04 LTS lucid | Not in release | |
8.04 LTS hardy | Not in release |
Notes
jdstrand
Diablo (in Ubuntu 11.10) not affected per upstream also affects v2 api in Folsom+ (Ubuntu 12.10+)
Patch details
References
Related Ubuntu Security Notices (USN)
- USN-1626-1
- Glance vulnerability
- 8 November 2012
- USN-1626-2
- Glance vulnerability
- 9 November 2012