Nova VMware instance in resize state may leak

2014.10.22
Risk: Medium
Local: Yes
Remote: No
CWE: CWE-399


Ogólna skala CVSS: 4/10
Znaczenie: 2.9/10
Łatwość wykorzystania: 8/10
Wymagany dostęp: Zdalny
Złożoność ataku: Niska
Autoryzacja: Jednorazowa
Wpływ na poufność: Brak
Wpływ na integralność: Brak
Wpływ na dostępność: Częściowy

OpenStack Security Advisory: 2014-037 CVE: CVE-2014-8333 Date: October 21, 2014 Title: Nova VMware instance in resize state may leak Reporter: Zhu Zhu (IBM) Products: Nova Versions: up to 2014.1.3 Description: Zhu Zhu from IBM reported a vulnerability in Nova VMware driver. If an authenticated user deletes an instance while it is in resize state, it will cause the original instance to not be deleted. An attacker can use this to launch a denial of service attack. All Nova VMware setups are affected. Juno fix: https://review.openstack.org/118595 Icehouse fix: https://review.openstack.org/125492 Notes: This fix was included in the 2014.2 release and will appear in a future 2014.1.4 stable point release. References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8333 https://launchpad.net/bugs/1359138 -- Tristan Cacqueray OpenStack Vulnerability Management Team

Referencje:

https://review.openstack.org/118595
https://review.openstack.org/125492


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top