CVE-2013-6433
Publication date 2 June 2014
Last updated 24 July 2024
Ubuntu priority
The default configuration in the Red Hat openstack-neutron package before 2013.2.3-7 does not properly set a configuration file for rootwrap, which allows remote attackers to gain privileges via a crafted configuration file.
Status
Package | Ubuntu Release | Status |
---|---|---|
neutron | 14.04 LTS trusty |
Fixed 1:2014.1-0ubuntu1.3
|
quantum | 14.04 LTS trusty | Not in release |
Notes
jdstrand
medium because while the issue is privilege escalation, it requires another flaw to exploit the Ubuntu 14.10 1:2014.2~b1-0ubuntu3 upload mistakenly references CVE-2013-1068
References
Related Ubuntu Security Notices (USN)
- USN-2255-1
- OpenStack Neutron vulnerabilities
- 25 June 2014