Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.841598
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-2000-1)
Summary:The remote host is missing an update for the 'nova' package(s) announced via the USN-2000-1 advisory.
Description:Summary:
The remote host is missing an update for the 'nova' package(s) announced via the USN-2000-1 advisory.

Vulnerability Insight:
It was discovered that Nova did not properly enforce the is_public property
when determining flavor access. An authenticated attacker could exploit
this to obtain sensitive information in private flavors. This issue only
affected Ubuntu 12.10 and 13.10. (CVE-2013-2256, CVE-2013-4278)

Grant Murphy discovered that Nova would allow XML entity processing. A
remote unauthenticated attacker could exploit this using the Nova API to
cause a denial of service via resource exhaustion. This issue only
affected Ubuntu 13.10. (CVE-2013-4179)

Vishvananda Ishaya discovered that Nova inefficiently handled network
security group updates when Nova was configured to use nova-network. An
authenticated attacker could exploit this to cause a denial of service.
(CVE-2013-4185)

Jaroslav Henner discovered that Nova did not properly handle certain inputs
to the instance console when Nova was configured to use Apache Qpid. An
authenticated attacker could exploit this to cause a denial of service on
the compute node running the instance. By default, Ubuntu uses RabbitMQ
instead of Qpid. (CVE-2013-4261)

Affected Software/OS:
'nova' package(s) on Ubuntu 12.04, Ubuntu 12.10, Ubuntu 13.04.

Solution:
Please install the updated package(s).

CVSS Score:
6.0

CVSS Vector:
AV:N/AC:M/Au:S/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-2256
RHSA-2013:1199
http://rhn.redhat.com/errata/RHSA-2013-1199.html
[oss-security] 20130806 [OSSA 2013-019] Resource limit circumvention in Nova private flavors (CVE-2013-2256)
http://seclists.org/oss-sec/2013/q3/281
https://bugs.launchpad.net/nova/+bug/1194093
Common Vulnerability Exposure (CVE) ID: CVE-2013-4179
USN-2005-1
http://www.ubuntu.com/usn/USN-2005-1
https://bugs.launchpad.net/ossa/+bug/1190229
Common Vulnerability Exposure (CVE) ID: CVE-2013-4185
[oss-secuirty] 20130806 [OSSA 2013-020] Denial of Service in Nova network source security groups (CVE-2013-4185)
http://seclists.org/oss-sec/2013/q3/282
https://bugs.launchpad.net/nova/+bug/1184041
Common Vulnerability Exposure (CVE) ID: CVE-2013-4261
[oss-security] 20130912 [OSSA 2013-026] Potential denial of service on Nova when using Qpid (CVE-2013-4261)
http://seclists.org/oss-sec/2013/q3/595
https://bugs.launchpad.net/nova/+bug/1215091
https://bugzilla.redhat.com/show_bug.cgi?id=999164
https://bugzilla.redhat.com/show_bug.cgi?id=999271
Common Vulnerability Exposure (CVE) ID: CVE-2013-4278
[openstack-announce] 20130828 [OSSA 2013-024] Resource limit circumvention in Nova private flavors (CVE-2013-4278)
http://lists.openstack.org/pipermail/openstack-announce/2013-August/000138.html
https://bugs.launchpad.net/ossa/+bug/1212179
CopyrightCopyright (C) 2013 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.