Description
The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-0145 | The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision. |
Github GHSA |
GHSA-wmhw-fvg9-87fc | OpenStack Glance Signature Verification Bypass |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T08:13:31.678Z
Reserved: 2015-11-18T00:00:00.000Z
Link: CVE-2015-8234
No data.
Status : Modified
Published: 2017-03-29T14:59:00.267
Modified: 2026-05-13T00:24:29.033
Link: CVE-2015-8234
OpenCVE Enrichment
No data.
EUVD
Github GHSA