virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Diablo | Openstack | 2011.3 (including) | 2011.3 (including) |
Essex | Openstack | 2012.1 (including) | 2012.1 (including) |
Folsom | Openstack | 2012.2 (including) | 2012.2 (including) |
Nova | Ubuntu | natty | * |
Nova | Ubuntu | oneiric | * |
Nova | Ubuntu | precise | * |