Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 482144 (CVE-2013-4278)

Summary: <sys-cluster/nova-{2012.2.4-r8,2013.1.3-r5} : private flavors resource limit circumvention incomplete fix for CVE-2013-2256
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: trivial    
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://bugzilla.redhat.com/show_bug.cgi?id=1000086
Whiteboard: ~3 [noglsa]
Package list:
Runtime testing required: ---

Description Agostino Sarubbo gentoo-dev 2013-08-22 20:21:40 UTC
From ${URL} :

Vincent Danen (vdanen@redhat.com) reports:

The previous fix was insufficient and did not fully fix the flaw, as noted here:

https://bugs.launchpad.net/ossa/+bug/1212179

The patch to fully correct this flaw is here (I believe it would be in addition to 
previously-mentioned patches):

https://github.com/openstack/nova/commit/4054cc4a22a1fea997dec76afb5646fd6c6ea6b9


@maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not.
Comment 2 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2013-09-12 06:56:15 UTC
fixed in 2012.2.4-r8 and 2013.1.3-r5  badness removed

removing myself from cc
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2013-09-17 22:34:38 UTC
CVE-2013-4278 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4278):
  The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly,
  and Havana does not properly enforce the os-flavor-access:is_public
  property, which allows remote authenticated users to boot arbitrary flavors
  by guessing the flavor id.  NOTE: this issue is due to an incomplete fix for
  CVE-2013-2256.