Comment 50 for bug 1415087

Revision history for this message
Michael Still (mikal) wrote : Re: Format-guessing and file disclosure in image convert (CVE-2015-1850)

On the nova side, the recent slowness (to my understanding) is that we've had a lot of trouble actually finding an exploit for this. We agree there is a theoretical problem, but we haven't been able to actually replicate a working attack.

So... Nova needs to do some defensive work here, but that effort is not yet complete.