[ubuntu/precise] nova 2012.1~e2~20111208.11721-0ubuntu3 (Accepted)
Jamie Strandboge
jamie at ubuntu.com
Tue Dec 13 15:25:19 UTC 2011
nova (2012.1~e2~20111208.11721-0ubuntu3) precise; urgency=low
* SECURITY UPDATE: fix directory traversal during image registration via
EC2 API and S3/RegisterImage
- fix-traversal-via-image-register.patch: adjust nova/image/s3.py to
use basename instead of absolute path
- CVE-2011-4596
Date: Tue, 13 Dec 2011 08:39:13 -0600
Changed-By: Jamie Strandboge <jamie at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/precise/+source/nova/2012.1~e2~20111208.11721-0ubuntu3
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 13 Dec 2011 08:39:13 -0600
Source: nova
Binary: python-nova nova-common nova-compute nova-compute-lxc nova-compute-uml nova-compute-xen nova-compute-kvm nova-scheduler nova-volume nova-ajax-console-proxy nova-vncproxy nova-api nova-network nova-objectstore nova-console nova-doc
Architecture: source
Version: 2012.1~e2~20111208.11721-0ubuntu3
Distribution: precise
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Jamie Strandboge <jamie at ubuntu.com>
Description:
nova-ajax-console-proxy - OpenStack Compute - AJAX console proxy
nova-api - OpenStack Compute - API frontend
nova-common - OpenStack Compute - common files
nova-compute - OpenStack Compute - compute node
nova-compute-kvm - OpenStack Compute - compute node (KVM)
nova-compute-lxc - OpenStack Compute - compute node (LXC)
nova-compute-uml - OpenStack Compute - compute node (UserModeLinux)
nova-compute-xen - OpenStack Compute - compute node (Xen)
nova-console - OpenStack Compute - Console
nova-doc - OpenStack Compute - documetation
nova-network - OpenStack Compute - Network manager
nova-objectstore - OpenStack Compute - object store
nova-scheduler - OpenStack Compute - virtual machine scheduler
nova-vncproxy - OpenStack Compute - VNC proxy
nova-volume - OpenStack Compute - storage
python-nova - OpenStack Compute Python libraries
Changes:
nova (2012.1~e2~20111208.11721-0ubuntu3) precise; urgency=low
.
* SECURITY UPDATE: fix directory traversal during image registration via
EC2 API and S3/RegisterImage
- fix-traversal-via-image-register.patch: adjust nova/image/s3.py to
use basename instead of absolute path
- CVE-2011-4596
Checksums-Sha1:
8277ecb0eccbf343c2676abf6bb1e1a41e1de128 3481 nova_2012.1~e2~20111208.11721-0ubuntu3.dsc
85f844bc6b8c8210a09131032ad737bf4704baa1 20116 nova_2012.1~e2~20111208.11721-0ubuntu3.debian.tar.gz
Checksums-Sha256:
6ac70541cfcb346ff4662f85f87d89216153ec3143828a97f2a8dcff7ba7a5fb 3481 nova_2012.1~e2~20111208.11721-0ubuntu3.dsc
ccee529bf547e67f931a8e3f7675efb45ca683f4ef2d5caa8e65a5e2db4f42c9 20116 nova_2012.1~e2~20111208.11721-0ubuntu3.debian.tar.gz
Files:
ed42e826e39fd147a064784114806580 3481 net extra nova_2012.1~e2~20111208.11721-0ubuntu3.dsc
1d52d2a2ccf681cef84a0cfeed0abaed 20116 net extra nova_2012.1~e2~20111208.11721-0ubuntu3.debian.tar.gz
Original-Maintainer: Openstack Maintainers <openstack at lists.launchpad.net>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
iQIcBAEBCgAGBQJO52wwAAoJEFHb3FjMVZVzM+wP/iE7w/w5fVrH+xi6AiSc1Ovs
YVD2wiok+zw5E5nQ6LDI33LtyVRJbJOqVPUMFwWzqYUS4px2ip7BVvYZuIEJ+LZe
rfduhPWJhAJ0a7UzB4PoUa4MCqilDXrLLgxfI52qCCoxX6o7Tl+adY+0Jw6S/qy5
cWilKXlDIqHJYn4VUc+As3yM6j9nKopGrsp3TyyXhzbBhg08NqzDky/1V0iHiinK
isNAK7EwME3YZ1LN68qjky7yOrEpZiQefqgOPR64i8BzZA2jm/PPSJz/GmsTI4sU
uoq9zDTRs+DtsQ9ZSph8nlRLRD2+ZnyZnpCWZxjSqIyZWXZ6yt43QlYgceae+llK
gJWvsRFZqoognBPyfT6bo410qxsCa3M4NTqMH2kkMpPa3DVz9YsAer+t8YEI+zGR
xfEip7P7FHS+91bxO5UFO0tGOauNcYFEzkklZbw+6SvjbUaEqIumptaDvTU+iERp
4ts38bXRg/aNx1cTZ5G0xikR78S62rrzSHbJ1cBLRHYRGoIiye1s5i3SCG5sjixz
bDuKSg0HTyahRAhpem97Dfsfpu+EPxXSFazxNutOJQi0ZQ5ZAMlKXMnybz8NecTo
eTcaxAd1eNIa07f79N6BY4Zjif9mZvosbMKeQijzKpq4Uw2rW7FWslbPxRFJmR+Q
SKoKD+6SP6WsCdONtWwQ
=BKVV
-----END PGP SIGNATURE-----
More information about the Precise-changes
mailing list