========================================================================== Ubuntu Security Notice USN-2249-1 June 18, 2014 heat vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: OpenStack Heat would expose sensitive information over the network. Software Description: - heat: OpenStack Orchestration Service Details: Jason Dunsmore discovered that OpenStack heat did not properly restrict access to template information. A remote authenticated attacker could exploit this to see URL provider templates of other tenants for a limited time. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: python-heat 2014.1-0ubuntu1.1 In general, a standard system update will make all the necessary changes. References: http://www.ubuntu.com/usn/usn-2249-1 CVE-2014-3801 Package Information: https://launchpad.net/ubuntu/+source/heat/2014.1-0ubuntu1.1