Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.71631
Category:Ubuntu Local Security Checks
Title:Ubuntu USN-1466-1 (python-nova)
Summary:NOSUMMARY
Description:Description:
The remote host is missing an update to python-nova
announced via advisory USN-1466-1.

Details:

It was discovered that, when defining security groups in Nova using
the EC2 or OS APIs, specifying the network protocol (e.g. 'TCP') in
the incorrect case would cause the security group to not be applied
correctly. An attacker could use this to bypass Nova security group
restrictions.

Solution:
The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
python-nova 2011.3-0ubuntu6.7

http://www.securityspace.com/smysecure/catid.html?in=USN-1466-1

CVSS Score:
4.3

CVSS Vector:
AV:L/AC:H/Au:NR/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-2654
46808
http://secunia.com/advisories/46808
49439
http://secunia.com/advisories/49439
USN-1466-1
http://www.ubuntu.com/usn/USN-1466-1
[openstack] 20120606 [OSSA 2012-007] Security groups fail to be set correctly (CVE-2012-2654)
https://lists.launchpad.net/openstack/msg12883.html
https://bugs.launchpad.net/nova/+bug/985184
https://github.com/openstack/nova/commit/9f9e9da777161426a6f8cb4314b78e09beac2978
https://github.com/openstack/nova/commit/ff06c7c885dc94ed7c828e8cdbb8b5d850a7e654
https://review.openstack.org/#/c/8239/
nova-security-group-sec-bypass(76110)
https://exchange.xforce.ibmcloud.com/vulnerabilities/76110
CopyrightCopyright (c) 2012 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.