Re: [Openstack] [OSSA 2012-007] Security groups fail to be set correctly (CVE-2012-2654)

2012-06-11 Thread Russell Bryant
Greetings, A regression was discovered in the patch that was committed to resolve this security issue. See this bug for the regression: https://bugs.launchpad.net/nova/+bug/1010514 Please see the following links for the fixes: Folsom: https://github.com/openstack/nova/commit/bbdf82c5ec3e31a5dc

[Openstack] [OSSA 2012-007] Security groups fail to be set correctly (CVE-2012-2654)

2012-06-06 Thread Russell Bryant
OpenStack Security Advisory: 2012-007 CVE: 2012-2654 Date: June 6, 2012 Title: Security groups fail to be set correctly Impact: Medium Reporter: HP Cloud Services hpcs.secur...@hp.com Products: Nova Affects: All versions Description: HP Cloud Services reported a vulnerability in Nova API handling.