Safety vulnerability ID: 35563
The information on this page was manually curated by our Cybersecurity Intelligence Team.
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.
Latest version: 30.0.0
Cloud computing fabric controller
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.
MLIST:[oss-security] 20141002 [OSSA 2014-032] Nova VMware driver still leaks rescued images (CVE-2014-3608): http://seclists.org/oss-sec/2014/q4/65
CONFIRM:https://bugs.launchpad.net/nova/+bug/1338830: https://bugs.launchpad.net/nova/+bug/1338830
REDHAT:RHSA-2014:1781: http://rhn.redhat.com/errata/RHSA-2014-1781.html
REDHAT:RHSA-2014:1782: http://rhn.redhat.com/errata/RHSA-2014-1782.html
BID:70220: http://www.securityfocus.com/bid/70220
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application