CVE Vulnerabilities

CVE-2013-1068

Published: Jun 19, 2014 | Modified: Jun 20, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The OpenStack Nova (python-nova) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.2 and 1:2014.1-0 before 1:2014.1-0ubuntu1.2 and Openstack Cinder (python-cinder) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.1 and 1:2014.1-0 before 1:2014.1-0ubuntu1.1 for Ubuntu 13.10 and 14.04 LTS does not properly set the sudo configuration, which makes it easier for attackers to gain privileges by leveraging another vulnerability.

Affected Software

Name Vendor Start Version End Version
Ubuntu_linux Canonical 13.10 (including) 13.10 (including)
Ubuntu_linux Canonical 14.04 (including) 14.04 (including)
Cinder Ubuntu devel *
Cinder Ubuntu saucy *
Cinder Ubuntu trusty *
Nova Ubuntu devel *
Nova Ubuntu saucy *
Nova Ubuntu trusty *

References