Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.841078
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-1501-1)
Summary:The remote host is missing an update for the 'nova' package(s) announced via the USN-1501-1 advisory.
Description:Summary:
The remote host is missing an update for the 'nova' package(s) announced via the USN-1501-1 advisory.

Vulnerability Insight:
Dan Prince discovered that the Nova scheduler, when using
DifferentHostFilter or SameHostFilter, would make repeated database
instance lookup calls based on passed scheduler hints. An authenticated
attacker could use this to cause a denial of service.

Affected Software/OS:
'nova' package(s) on Ubuntu 12.04.

Solution:
Please install the updated package(s).

CVSS Score:
3.5

CVSS Vector:
AV:N/AC:M/Au:S/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-3371
54388
http://www.securityfocus.com/bid/54388
USN-1501-1
http://www.ubuntu.com/usn/USN-1501-1
[openstack] 20120711 [OSSA 2012-009] Scheduler denial of service through scheduler_hints (CVE-2012-3371)
https://lists.launchpad.net/openstack/msg14452.html
[oss-security] 20120711 [OSSA 2012-009] Scheduler denial of service through scheduler_hints (CVE-2012-3371)
http://www.openwall.com/lists/oss-security/2012/07/11/13
https://bugs.launchpad.net/nova/+bug/1017795
https://github.com/openstack/nova/commit/034762e8060dcf0a11cb039b9d426b0d0bb1801d
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.