PyPi: Nova

CVE-2012-3447

Safety vulnerability ID: 35368

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Aug 20, 2012 Updated at Oct 24, 2024
Scan your Python projects for vulnerabilities →

Advisory

virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by root. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3361.

Affected package

nova

Latest version: 30.0.0

Cloud computing fabric controller

Affected versions

Fixed versions

Vulnerability changelog

virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by root. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3361.


MLIST:[oss-security] 20120807 [OSSA 2012-011] Compute node filesystem injection/corruption (CVE-2012-3447): http://www.openwall.com/lists/oss-security/2012/08/07/1
MISC:https://bugzilla.redhat.com/show_bug.cgi?id=845106: https://bugzilla.redhat.com/show_bug.cgi?id=845106
CONFIRM:https://bugs.launchpad.net/nova/+bug/1031311: https://bugs.launchpad.net/nova/+bug/1031311
CONFIRM:https://github.com/openstack/nova/commit/ce4b2e27be45a85b310237615c47eb53f37bb5f3: https://github.com/openstack/nova/commit/ce4b2e27be45a85b310237615c47eb53f37bb5f3
CONFIRM:https://github.com/openstack/nova/commit/d9577ce9f266166a297488445b5b0c93c1ddb368: https://github.com/openstack/nova/commit/d9577ce9f266166a297488445b5b0c93c1ddb368
CONFIRM:https://review.openstack.org/#/c/10953/: https://review.openstack.org/#/c/10953/
BID:54869: http://www.securityfocus.com/bid/54869
XF:openstack-nova-code-execution(77539): https://exchange.xforce.ibmcloud.com/vulnerabilities/77539

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

MEDIUM 4.9

CVSS v2 Details

MEDIUM 4.9
Access Vector (AV)
NETWORK
Access Complexity (AC)
MEDIUM
Authentication (Au)
SINGLE
Confidentiality Impact (C)
NONE
Integrity Impact (I)
PARTIAL
Availability Impact (A)
PARTIAL