Summary: | <sys-cluster/nova-2014.1-r2: VMWare driver leaks rescued images (CVE-2014-2573) (OSSA 2014-017) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | trivial | ||
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.openwall.com/lists/oss-security/2014/05/29/14 | ||
Whiteboard: | ~3 [noglsa] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
2014-06-03 14:24:57 UTC
icehouse fixed in nova-2014.1-r2.ebuild but we remain vulnerable in nova-2013.2.3-r2.ebuild. They have touched that file so much they don't have a clean patch to apply to it to fix the cve... (In reply to Matthew Thode ( prometheanfire ) from comment #1) > icehouse fixed in nova-2014.1-r2.ebuild but we remain vulnerable in > nova-2013.2.3-r2.ebuild. They have touched that file so much they don't > have a clean patch to apply to it to fix the cve... nova-2014.1-r2.ebuild patch reverted two previous revisions ... :( what did it revert? removed 2013.2.3.* from tree, removing myself from bug since I'm done here Maintainer(s), Thank you for cleanup! No GLSA needed as there are no stable versions. CVE-2014-2573 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-2573): The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not properly put VMs into RESCUE status, which allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by requesting the VM be put into rescue and then deleting the image. |