Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.71791
Category:Ubuntu Local Security Checks
Title:Ubuntu USN-1501-1 (python-nova)
Summary:NOSUMMARY
Description:Description:
The remote host is missing an update to python-nova
announced via advisory USN-1501-1.

Details:

Dan Prince discovered that the Nova scheduler, when using
DifferentHostFilter or SameHostFilter, would make repeated database
instance lookup calls based on passed scheduler hints. An authenticated
attacker could use this to cause a denial of service.

Solution:
The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
python-nova 2012.1+stable~
20120612-3ee026e-0ubuntu1.2

http://www.securityspace.com/smysecure/catid.html?in=USN-1501-1

CVSS Score:
3.5

CVSS Vector:
AV:L/AC:H/Au:R/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-3371
54388
http://www.securityfocus.com/bid/54388
USN-1501-1
http://www.ubuntu.com/usn/USN-1501-1
[openstack] 20120711 [OSSA 2012-009] Scheduler denial of service through scheduler_hints (CVE-2012-3371)
https://lists.launchpad.net/openstack/msg14452.html
[oss-security] 20120711 [OSSA 2012-009] Scheduler denial of service through scheduler_hints (CVE-2012-3371)
http://www.openwall.com/lists/oss-security/2012/07/11/13
https://bugs.launchpad.net/nova/+bug/1017795
https://github.com/openstack/nova/commit/034762e8060dcf0a11cb039b9d426b0d0bb1801d
CopyrightCopyright (c) 2012 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.