Comment 49 for bug 1415087

Revision history for this message
Dave Walker (davewalker) wrote : Re: Format-guessing and file disclosure in image convert (CVE-2015-1850)

My understanding from the history is that Cinder's patch is ready and reviewed but the Nova issue is still a problem, is this correct?

Now this issue is disclosed and public, I think we need to raise the urgency of some code mitigation/workaround?

Eric, as the issue is now public - worth pushing your patch to gerrit?