Nova: Compressed disk image DoS
Published Feb 6, 2014
2.1
LOWCVSS 2.0
EPSS 0.37%
Description
OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) via a compressed QCOW2 image. NOTE: this issue is due to an incomplete fix for CVE-2013-2096.
Affected products
No data.
No data.
OpenStack 3 for RHEL 6
openstack-nova-0:2013.1.4-4.el6ost
Fixed · RHSA-2014:0112
Red Hat OpenStack Platform 4
openstack-nova
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenStack 3 for RHEL 6 | openstack-nova-0:2013.1.4-4.el6ost | Fixed | RHSA-2014:0112 |
| Red Hat OpenStack Platform 4 | openstack-nova | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The Red Hat Security Response Team has rated this issue as having moderate security impact. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
References (11)
- http://github.com/openstack/nova/commit/3cdfe894ab58f7b91bf7fb690fc5bc724e44066f
- http://github.com/openstack/nova/commit/f6810be4ae1a6c93e7d8017ee67d5344dfdf4a30
- http://rhn.redhat.com/errata/RHSA-2014-0112.html vendor-advisoryx_refsource_REDHAT
- http://www.openwall.com/lists/oss-security/2013/10/31/3 mailing-listx_refsource_MLIST
- http://www.ubuntu.com/usn/USN-2247-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2013-4463 Vendor Advisory
- https://bugs.launchpad.net/nova/+bug/1206081 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=1023239 Issue Tracking
- https://github.com/advisories/GHSA-5644-2v3h-5w4x Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-4463
- https://www.cve.org/CVERecord?id=CVE-2013-4463
| Link | Providers | Tags |
|---|---|---|
| http://github.com/openstack/nova/commit/3cdfe894ab58f7b91bf7fb690fc5bc724e44066f | ||
| http://github.com/openstack/nova/commit/f6810be4ae1a6c93e7d8017ee67d5344dfdf4a30 | ||
| http://rhn.redhat.com/errata/RHSA-2014-0112.html | vendor-advisoryx_refsource_REDHAT | |
| http://www.openwall.com/lists/oss-security/2013/10/31/3 | mailing-listx_refsource_MLIST | |
| http://www.ubuntu.com/usn/USN-2247-1 | vendor-advisoryx_refsource_UBUNTU | |
| https://access.redhat.com/security/cve/CVE-2013-4463 | Vendor Advisory | |
| https://bugs.launchpad.net/nova/+bug/1206081 | x_refsource_CONFIRM | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1023239 | Issue Tracking | |
| https://github.com/advisories/GHSA-5644-2v3h-5w4x | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-4463 | ||
| https://www.cve.org/CVERecord?id=CVE-2013-4463 |
Change history (0)
No recorded changes yet.