Comment 41 for bug 1015531

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to nova (stable/diablo)

Reviewed: https://review.openstack.org/9268
Committed: http://github.com/openstack/nova/commit/1e218105b08b1afdf944fc77af91c2cadf90b6e2
Submitter: Jenkins
Branch: stable/diablo

commit 1e218105b08b1afdf944fc77af91c2cadf90b6e2
Author: Thierry Carrez <email address hidden>
Date: Tue Jul 3 16:34:58 2012 +0200

    Prevent key/net/md injection writing to host fs

    Fix bug 1015531, CVE-2012-3361

    Checks that the final normalized path that is about to be written
    to is always within the mounted guest filesystem.

    This is a Diablo backport of the part of Russell Bryant, Pádraig Brady
    and Mark McLoughlin's Folsom patch that applies to stable/diablo.

    Change-Id: I134c40258ff2c9c225bd6092decd9c10e4e22273