Comment 42 for bug 1996188

Revision history for this message
Dan Smith (danms) wrote : Re: Arbitrary file access through custom VMDK flat descriptor

Arnaud, yes, we should probably catch that and roll back the import. However, let's treat that as a separate non-security bug to avoid inflating the glance patch any further, since that's a latent but otherwise harmless issue. Glance also probably should be changed to use the oslo qemu info utility like the others, and so that'd be a good time to resolve this as well.