Vulnerability CVE-2013-7130


Published: 2014-02-06

Description:
The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, when using KVM live block migration, does not properly create all expected files, which allows attackers to obtain snapshot root disk contents of other users via ephemeral storage.

Type:

CWE-200

(Information Exposure)

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.1/10
6.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
None
None
Affected software
Openstack -> Compute 
Openstack -> Grizzly 
Openstack -> Havana 
Openstack -> Icehouse 

 References:
https://review.openstack.org/#/c/68660/
https://review.openstack.org/#/c/68658/
https://review.openstack.org/#/c/68659/
https://bugs.launchpad.net/nova/+bug/1251590
http://xforce.iss.net/xforce/xfdb/90652
http://www.ubuntu.com/usn/USN-2247-1
http://www.securityfocus.com/bid/65106
http://www.openwall.com/lists/oss-security/2014/01/23/5
http://secunia.com/advisories/56450
http://rhn.redhat.com/errata/RHSA-2014-0231.html
http://osvdb.org/102416
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127735.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127732.html

Copyright 2024, cxsecurity.com

 

Back to Top