OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via a large number of calls to the addFixedIp function.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 01:50
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/91303 - | |
References | () http://rhn.redhat.com/errata/RHSA-2013-0709.html - | |
References | () http://secunia.com/advisories/52580 - Vendor Advisory | |
References | () http://secunia.com/advisories/52728 - Vendor Advisory | |
References | () http://ubuntu.com/usn/usn-1771-1 - | |
References | () http://www.openwall.com/lists/oss-security/2013/03/14/18 - | |
References | () http://www.securityfocus.com/bid/58492 - | |
References | () https://bugs.launchpad.net/nova/+bug/1125468 - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=919648 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/82877 - | |
References | () https://lists.launchpad.net/openstack/msg21892.html - | |
References | () https://review.openstack.org/#/c/24451/ - | |
References | () https://review.openstack.org/#/c/24452/ - | |
References | () https://review.openstack.org/#/c/24453/ - |
Information
Published : 2013-03-22 21:55
Updated : 2024-11-21 01:50
NVD link : CVE-2013-1838
Mitre link : CVE-2013-1838
CVE.ORG link : CVE-2013-1838
JSON object : View
Products Affected
openstack
- folsom
- grizzly
- essex
canonical
- ubuntu_linux
CWE
CWE-399
Resource Management Errors