Comment 52 for bug 1415087

Revision history for this message
Tony Breeds (o-tony) wrote : Re: Format-guessing and file disclosure in image convert (CVE-2015-1850)

Mikal is correct nova has a theoretical issue but I've been unable to actually exploit it..

I've certainly been able to create a guest with an image that shows the problem BUT as yet I haven't been able to get nova to run convert on it.

A related issue is that nova blindly trusts qemu-img info which is itself susceptible to a similar issue.