ossa/ossa/OSSA-2013-008.yaml

61 lines
1.3 KiB
YAML

date: 2013-03-14
id: OSSA-2013-008
title: 'Nova DoS by allocating all Fixed IPs'
description: 'Vish Ishaya reported a vulnerability in Nova where there is no quota
for Fixed IPs. Previously the instance quota acted as a proxy for a Fixed IP quota,
but if your configuration allows an instance to consume more than one Fixed IP via
an extension such as multinic then this is no longer true. Running out of Fixed
IPs would result in not being able to spawn new instances.'
reference: http://lists.openstack.org/pipermail/openstack-announce/2013-March/000086.html
affected-products:
- product: nova
version: All versions
vulnerabilities:
- cve-id: CVE-2013-1838
impact-assessment:
source: 'Red Hat Product Security'
rating: low
assessment:
type: CVSS2
score: 4.3
detail: AV:N/AC:M/Au:N/C:N/I:N/A:P
classification:
source: 'Red Hat Product Security'
type: CWE
detail: TODO
reporters:
- name: 'Vish Ishaya'
affiliation: Nebula
reported:
- CVE-2013-1838
issues:
links:
- https://launchpad.net/bugs/1125468
type: launchpad
reviews:
grizzly:
- https://review.openstack.org/#/c/24451
folsom:
- https://review.openstack.org/#/c/24452
essex:
- https://review.openstack.org/#/c/24453
type: gerrit