Summary: | sys-cluster/nova: Security Bypass and Denial of Service Vulnerabilities (CVE-2013-{2256,4185}) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | trivial | ||
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://secunia.com/advisories/54397/ | ||
Whiteboard: | ~3 [noglsa] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
2013-08-07 11:22:44 UTC
nova-2012.2.4-r4 has the fix nova-2013.1.3 has the fix badness removed from tree This is valid for the following CVEs CVE-2013-2256 and CVE-2013-4185 I'm removing myself from CC, if you feel I should be re-added just re-add me and let me know why. This bug should be closable Okay, we're done then. Closing. CVE-2013-2256 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2256): OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor id. CVE-2013-4185 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4185): Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-3 does not properly handle network source security group policy updates, which allows remote authenticated users to cause a denial of service (nova-network consumption) via a large number of server-creation operations, which triggers a large number of update requests. |