Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS05MmhjLWMyMjYtMzJxN84AAU0U
OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.
Permalink: https://github.com/advisories/GHSA-92hc-c226-32q7JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05MmhjLWMyMjYtMzJxN84AAU0U
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 2 years ago
Updated: about 1 year ago
Identifiers: GHSA-92hc-c226-32q7, CVE-2014-3608
References:
- https://nvd.nist.gov/vuln/detail/CVE-2014-3608
- https://bugs.launchpad.net/nova/+bug/1338830
- http://rhn.redhat.com/errata/RHSA-2014-1781.html
- http://rhn.redhat.com/errata/RHSA-2014-1782.html
- http://seclists.org/oss-sec/2014/q4/65
- https://access.redhat.com/errata/RHSA-2014:1781
- https://access.redhat.com/errata/RHSA-2014:1782
- https://access.redhat.com/security/cve/CVE-2014-3608
- https://bugzilla.redhat.com/show_bug.cgi?id=1148253
- https://web.archive.org/web/20200228053850/http://www.securityfocus.com/bid/70220
- http://www.securityfocus.com/bid/70220
- https://github.com/advisories/GHSA-92hc-c226-32q7
Affected Packages
pypi:nova
Dependent packages: 0Dependent repositories: 40
Downloads: 3,670 last month
Affected Version Ranges: < 2014.1.3
Fixed in: 2014.1.3
All affected versions: 15.1.5, 16.1.6, 16.1.7, 16.1.8, 17.0.7, 17.0.8, 17.0.9, 17.0.10, 17.0.11, 17.0.12, 17.0.13, 18.0.2, 18.0.3, 18.1.0, 18.2.0, 18.2.1, 18.2.2, 18.2.3, 18.3.0, 19.0.0, 19.0.1, 19.0.2, 19.0.3, 19.1.0, 19.2.0, 19.3.0, 19.3.1, 19.3.2, 20.0.0, 20.0.1, 20.1.0, 20.1.1, 20.2.0, 20.3.0, 20.4.0, 20.4.1, 20.5.0, 20.6.0, 20.6.1, 21.0.0, 21.1.0, 21.1.1, 21.1.2, 21.2.0, 21.2.1, 21.2.2, 21.2.3, 21.2.4, 22.0.0, 22.0.1, 22.1.0, 22.2.0, 22.2.1, 22.2.2, 22.3.0, 22.4.0, 23.0.0, 23.0.1, 23.0.2, 23.1.0, 23.2.0, 23.2.1, 23.2.2, 24.0.0, 24.1.0, 24.1.1, 24.2.0, 24.2.1, 25.0.0, 25.0.1, 25.1.0, 25.1.1, 25.2.0, 25.2.1, 25.3.0, 26.0.0, 26.1.0, 26.1.1, 26.2.0, 26.2.1, 26.2.2, 27.0.0, 27.1.0, 27.2.0, 28.0.0, 28.0.1, 29.0.0
All unaffected versions: