Vulnerability CVE-2015-3156

Published: 2017-08-11

The _write_config function in trove/guestagent/datastore/experimental/mongodb/, reset_configuration function in trove/guestagent/datastore/experimental/postgresql/service/, write_config function in trove/guestagent/datastore/experimental/redis/, _write_mycnf function in trove/guestagent/datastore/mysql/, InnoBackupEx::_run_prepare function in trove/guestagent/strategies/restore/, InnoBackupEx::cmd function in trove/guestagent/strategies/backup/, MySQLDump::cmd in trove/guestagent/strategies/backup/, InnoBackupExIncremental::cmd function in trove/guestagent/strategies/backup/, _get_actual_db_status function in trove/guestagent/datastore/experimental/cassandra/ and trove/guestagent/datastore/experimental/cassandra/, and multiple class CbBackup methods in trove/guestagent/strategies/backup/experimental/ in Openstack DBaaS (aka Trove) as packaged in Openstack before 2015.1.0 (aka Kilo) allows local users to write to configuration files via a symlink attack on a temporary file.

Vendor: Openstack
Product: Trove 
Version: 2014.2.4;

CVSS2 => (AV:L/AC:L/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
Exploit range
Attack complexity
No required
Confidentiality impact
Integrity impact
Availability impact


Related CVE
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doub...
An issue was discovered in in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and proxy server are saving (unhashed) tokens retrieved from the Swauth middleware authentication mechani...
In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, by rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filters (for example, the ImagePropertiesFilter or the I...
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used inse...
Designate 2015.1.0 through as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of servic...
Aodh as packaged in Openstack Ocata and Newton before change-ID I8fd11a7f9fe3c0ea5f9843a89686ac06713b7851 and before Pike-rc1 does not verify that trust IDs belong to the user when creating alarm action with the scheme trust+http, which allows remote...
OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails allows local users to access VM volumes that they would normally not have permissions for.
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made t...

Copyright 2018,


Back to Top