diff options
author | Jean-Pierre Giraud <jean-pierregiraud@neuf.fr> | 2023-02-02 01:02:03 +0100 |
---|---|---|
committer | Jean-Pierre Giraud <jean-pierregiraud@neuf.fr> | 2023-02-02 01:02:03 +0100 |
commit | 3d263cf076152e82cf021484ea38a52d64051f66 (patch) | |
tree | 83024d6d379094969e9f7584011367c67fdcaf12 | |
parent | d54d3fd27719787049b6ef067493048aa9bbac88 (diff) |
[SECURITY] [DSA 5336-1] glance security update
-rw-r--r-- | english/security/2023/dsa-5336.data | 13 | ||||
-rw-r--r-- | english/security/2023/dsa-5336.wml | 21 |
2 files changed, 34 insertions, 0 deletions
diff --git a/english/security/2023/dsa-5336.data b/english/security/2023/dsa-5336.data new file mode 100644 index 00000000000..94eadfb946d --- /dev/null +++ b/english/security/2023/dsa-5336.data @@ -0,0 +1,13 @@ +<define-tag pagetitle>DSA-5336-1 glance</define-tag> +<define-tag report_date>2023-2-01</define-tag> +<define-tag secrefs>CVE-2022-47951 Bug#1029563</define-tag> +<define-tag packages>glance</define-tag> +<define-tag isvulnerable>yes</define-tag> +<define-tag fixed>yes</define-tag> +<define-tag fixed-section>no</define-tag> + +#use wml::debian::security + + + +</dl> diff --git a/english/security/2023/dsa-5336.wml b/english/security/2023/dsa-5336.wml new file mode 100644 index 00000000000..1a129d0ad15 --- /dev/null +++ b/english/security/2023/dsa-5336.wml @@ -0,0 +1,21 @@ +<define-tag description>security update</define-tag> +<define-tag moreinfo> +<p>Guillaume Espanel, Pierre Libeau, Arnaud Morin and Damien Rannou +discovered that missing input sanitising in the handling of VMDK images +in Glance, the OpenStack image registry and delivery service, may result +in information disclosure.</p> + +<p>For the stable distribution (bullseye), this problem has been fixed in +version 2:21.0.0-2+deb11u1.</p> + +<p>We recommend that you upgrade your glance packages.</p> + +<p>For the detailed security status of glance please refer to +its security tracker page at: +<a href="https://security-tracker.debian.org/tracker/glance">\ +https://security-tracker.debian.org/tracker/glance</a></p> +</define-tag> + +# do not modify the following line +#include "$(ENGLISHDIR)/security/2023/dsa-5336.data" +# $Id: $ |