ossa/ossa/OSSA-2012-020.yaml

58 lines
1.3 KiB
YAML

date: 2012-12-11
id: OSSA-2012-020
title: 'Information leak in libvirt LVM-backed instances'
description: 'Eric Windisch from Cloudscaling reported a vulnerability in libvirt
LVM-backed instances. The physical volume content was not wiped out before being
deallocated and passed to an instance, which may result in the disclosure of information
from previously-allocated logical volumes.Only setups using libvirt and LVM-backed
instances (libvirt_images_type=lvm) are affected. '
reference: http://lists.openstack.org/pipermail/openstack-announce/2012-December/000059.html
affected-products:
- product: nova
version: Folsom, Grizzly
vulnerabilities:
- cve-id: CVE-2012-5625
impact-assessment:
source: 'Red Hat Product Security'
rating: low
assessment:
type: CVSS2
score: 1.5
detail: AV:L/AC:M/Au:S/C:P/I:N/A:N
classification:
source: 'Red Hat Product Security'
type: CWE
detail: TODO
reporters:
- name: 'Eric Windisch'
affiliation: Cloudscaling
reported:
- CVE-2012-5625
issues:
links:
- https://launchpad.net/bugs/1070539
type: launchpad
reviews:
grizzly:
- https://review.openstack.org/#/c/17856
folsom:
- https://review.openstack.org/#/c/17857
type: gerrit