CVE-2014-7230
Publication date 8 October 2014
Last updated 24 July 2024
Ubuntu priority
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
Status
Package | Ubuntu Release | Status |
---|---|---|
cinder | ||
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Fixed 1:2014.1.3-0ubuntu1
|
|
nova | ||
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Fixed 1:2014.1.3-0ubuntu1
|
|
trove | ||
18.04 LTS bionic | Ignored | |
16.04 LTS xenial | Ignored | |
14.04 LTS trusty | Not in release | |
Notes
Patch details
Package | Patch details |
---|---|
cinder |
|
nova |
|
trove |
|
References
Related Ubuntu Security Notices (USN)
- USN-2407-1
- OpenStack Nova vulnerabilities
- 11 November 2014
- USN-2405-1
- OpenStack Cinder vulnerabilities
- 11 November 2014