61 lines
1.3 KiB
YAML
61 lines
1.3 KiB
YAML
date: 2013-03-14
|
|
|
|
id: OSSA-2013-008
|
|
|
|
title: 'Nova DoS by allocating all Fixed IPs'
|
|
|
|
description: 'Vish Ishaya reported a vulnerability in Nova where there is no quota
|
|
for Fixed IPs. Previously the instance quota acted as a proxy for a Fixed IP quota,
|
|
but if your configuration allows an instance to consume more than one Fixed IP via
|
|
an extension such as multinic then this is no longer true. Running out of Fixed
|
|
IPs would result in not being able to spawn new instances.'
|
|
|
|
reference: http://lists.openstack.org/pipermail/openstack-announce/2013-March/000086.html
|
|
|
|
affected-products:
|
|
|
|
- product: nova
|
|
version: All versions
|
|
|
|
vulnerabilities:
|
|
|
|
- cve-id: CVE-2013-1838
|
|
impact-assessment:
|
|
source: 'Red Hat Product Security'
|
|
rating: low
|
|
assessment:
|
|
type: CVSS2
|
|
score: 4.3
|
|
detail: AV:N/AC:M/Au:N/C:N/I:N/A:P
|
|
classification:
|
|
source: 'Red Hat Product Security'
|
|
type: CWE
|
|
detail: TODO
|
|
|
|
reporters:
|
|
|
|
- name: 'Vish Ishaya'
|
|
affiliation: Nebula
|
|
reported:
|
|
- CVE-2013-1838
|
|
|
|
issues:
|
|
|
|
links:
|
|
- https://launchpad.net/bugs/1125468
|
|
|
|
type: launchpad
|
|
|
|
reviews:
|
|
|
|
grizzly:
|
|
- https://review.openstack.org/#/c/24451
|
|
|
|
folsom:
|
|
- https://review.openstack.org/#/c/24452
|
|
|
|
essex:
|
|
- https://review.openstack.org/#/c/24453
|
|
|
|
type: gerrit
|