ossa/ossa/OSSA-2014-032.yaml

63 lines
1.4 KiB
YAML

date: 2014-10-02
id: OSSA-2014-032
title: 'Nova VMware driver still leaks rescued images'
description: 'Garth Mollett from Red Hat reported an incomplete fix
to OSSA-2014-017 (CVE-2014-2573), a vulnerability affecting Nova.
If an authenticated user places an instance into rescue, and then
issues a suspend command it will cause the instance to enter an
ERROR state. Nova does not clean up an instance in this state
correctly upon deletion. An attacker can use this to launch a
denial of service attack. Only setups using the Nova VMware
driver are affected by this flaw.'
reference: http://lists.openstack.org/pipermail/openstack-announce/2014-October/000287.html
affected-products:
- product: nova
version: up to 2014.1.2
vulnerabilities:
- cve-id: CVE-2014-3608
impact-assessment:
source: 'Red Hat Product Security'
rating: moderate
assessment:
type: CVSS2
score: 4.0
detail: AV:N/AC:L/Au:S/C:N/I:N/A:P
classification:
source: 'Red Hat Product Security'
type: CWE
detail: CWE-772
reporters:
- name: 'Garth Mollett'
affiliation: Red Hat
reported:
- CVE-2014-3608
issues:
links:
- https://launchpad.net/bugs/1338830
type: launchpad
reviews:
juno:
- https://review.openstack.org/94281
icehouse:
- https://review.openstack.org/109624
type: gerrit