CVE-2014-0162
published 2014-04-27CVE-2014-0162: The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote…
PriorityP434medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
1.99%
78.3th percentile
The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to execute arbitrary commands via a crafted location.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glance | < glance 2014.1-1 (bookworm) | glance 2014.1-1 (bookworm) |
| glance_project | glance | >= 0 < 2014.1-1 | 2014.1-1 |
| glance_project | glance | >= 0 < 2014.1-1 | 2014.1-1 |
| glance_project | glance | >= 0 < 2014.1-1 | 2014.1-1 |
| glance_project | glance | >= 0 < 2014.1-1 | 2014.1-1 |
| glance_project | glance | >= 2013.2 < 2013.2.4 | 2013.2.4 |
| openstack | icehouse | — | — |
| openstack | image_registry_and_delivery_service | — | — |
| openstack | image_registry_and_delivery_service | — | — |
| openstack | image_registry_and_delivery_service | — | — |
| openstack | image_registry_and_delivery_service | — | — |
CVSS provenance
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenStack icehouse Rc-1 Registry input validation (USN-2193-1 / Nessus ID 73972)
vuldb·2026-05-12·CVSS 6.0
CVE-2014-0162 [MEDIUM] OpenStack icehouse Rc-1 Registry input validation (USN-2193-1 / Nessus ID 73972)
A vulnerability classified as critical was found in OpenStack icehouse Rc-1. This impacts an unknown function of the component Registry. Executing a manipulation can lead to improper input validation.
This vulnerability is handled as CVE-2014-0162. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
GHSA
OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability
ghsa·2022-05-17
CVE-2014-0162 [MEDIUM] CWE-20 OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability
OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability
The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to execute arbitrary commands via a crafted location.
OSV
OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability
osv·2022-05-17
CVE-2014-0162 [MEDIUM] OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability
OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability
The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to execute arbitrary commands via a crafted location.
OSV
CVE-2014-0162: The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013
osv·2014-04-27·CVSS 6.0
CVE-2014-0162 [MEDIUM] CVE-2014-0162: The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013
The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to execute arbitrary commands via a crafted location.
Ubuntu
OpenStack Glance vulnerability
vendor_ubuntu·2014-05-05
CVE-2014-0162 OpenStack Glance vulnerability
Title: OpenStack Glance vulnerability
Summary: OpenStack Glance could be made to run programs as the glance user if it
processed a specially crafted request.
Paul McMillan discovered that the Sheepdog backend in OpenStack Glance did
not properly handle untrusted input. A remote authenticated attacker
exploit this to execute arbitrary commands as the glance user.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-glance: remote code execution in Glance Sheepdog backend
vendor_redhat·2014-04-10·CVSS 6.0
CVE-2014-0162 [MEDIUM] CWE-78 openstack-glance: remote code execution in Glance Sheepdog backend
openstack-glance: remote code execution in Glance Sheepdog backend
The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to execute arbitrary commands via a crafted location.
Package: openstack-glance (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Affected
Package: openstack-glance (Red Hat OpenStack Platform 3) - Not affected
Debian
CVE-2014-0162: glance - The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2...
vendor_debian·2014·CVSS 6.0
CVE-2014-0162 [MEDIUM] CVE-2014-0162: glance - The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2...
The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to execute arbitrary commands via a crafted location.
Scope: local
bookworm: resolved (fixed in 2014.1-1)
bullseye: resolved (fixed in 2014.1-1)
forky: resolved (fixed in 2014.1-1)
sid: resolved (fixed in 2014.1-1)
trixie: resolved (fixed in 2014.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0162 openstack-glance: remote code execution in Glance Sheepdog backend [fedora-20]
bugzilla·2014-04-11·CVSS 6.0
CVE-2014-0162 [MEDIUM] CVE-2014-0162 openstack-glance: remote code execution in Glance Sheepdog backend [fedora-20]
CVE-2014-0162 openstack-glance: remote code execution in Glance Sheepdog backend [fedora-20]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-20 tr
Bugzilla
CVE-2014-0162 openstack-glance: remote code execution in Glance Sheepdog backend
bugzilla·2014-04-08·CVSS 6.0
CVE-2014-0162 [MEDIUM] CVE-2014-0162 openstack-glance: remote code execution in Glance Sheepdog backend
CVE-2014-0162 openstack-glance: remote code execution in Glance Sheepdog backend
A flaw was found in the Glance Sheepdog backend. A user who is able to insert or modify Glance image metadata could use this flaw to execute arbitrary commands with the privileges of the user who is running the Glance service.
Versions 2013.2 up to 2013.2.3 are affected.
Acknowledgements:
Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Paul McMillan (Nebula) as the original reporter.
Discussion:
Public now:
http://www.openwall.com/lists/oss-security/2014/04/10/13
https://launchpad.net/bugs/1298698
Juno (development branch) fix:
https://review.openstack.org/86622
Icehouse (milestone-proposed branch) fix:
https://review.openstack.org/86625
Havana fix:
h
http://rhn.redhat.com/errata/RHSA-2014-0455.htmlhttp://www.openwall.com/lists/oss-security/2014/04/10/13http://www.ubuntu.com/usn/USN-2193-1https://launchpad.net/bugs/1298698http://rhn.redhat.com/errata/RHSA-2014-0455.htmlhttp://www.openwall.com/lists/oss-security/2014/04/10/13http://www.ubuntu.com/usn/USN-2193-1https://launchpad.net/bugs/1298698
2014-04-27
Published