CVE-2015-8234

medium
Published 2017-03-29 · Modified 2024-11-25
CVSS v3
5.5
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS v2
4.3
VIR risk
5.5

Description

The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.

Predictions

Exploit likelihood
55%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-8234

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://bugs.launchpad.net/glance/+bug/1516031

OS impact

OSVersionStatusFixed in
debian debianbookwormaffected
debian debianbullseyeaffected
debian debianforkyaffected
debian debiansidaffected
debian debiantrixieaffected

Package impact

EcosystemPackageVulnerableFixed
python PyPIglance<=11.0.0

Application impact

VendorProductVersionsFixed
openstackglance11.0.0

References

CWEs

CWE-310

Verify integrity in audit chain (admin only). AS-IS.