Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.843332
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-3449-1)
Summary:The remote host is missing an update for the 'nova' package(s) announced via the USN-3449-1 advisory.
Description:Summary:
The remote host is missing an update for the 'nova' package(s) announced via the USN-3449-1 advisory.

Vulnerability Insight:
George Shuklin discovered that OpenStack Nova incorrectly handled the
migration process. A remote authenticated user could use this issue to
consume resources, resulting in a denial of service. (CVE-2015-3241)

George Shuklin and Tushar Patil discovered that OpenStack Nova incorrectly
handled deleting instances. A remote authenticated user could use this
issue to consume disk resources, resulting in a denial of service.
(CVE-2015-3280)

It was discovered that OpenStack Nova incorrectly limited qemu-img calls. A
remote authenticated user could use this issue to consume resources,
resulting in a denial of service. (CVE-2015-5162)

Matthew Booth discovered that OpenStack Nova incorrectly handled snapshots.
A remote authenticated user could use this issue to read arbitrary files.
(CVE-2015-7548)

Sreekumar S. and Suntao discovered that OpenStack Nova incorrectly applied
security group changes. A remote attacker could possibly use this issue to
bypass intended restriction changes by leveraging an instance that was
running when the change was made. (CVE-2015-7713)

Matt Riedemann discovered that OpenStack Nova incorrectly handled logging.
A local attacker could possibly use this issue to obtain sensitive
information from log files. (CVE-2015-8749)

Matthew Booth discovered that OpenStack Nova incorrectly handled certain
qcow2 headers. A remote authenticated user could possibly use this issue to
read arbitrary files. (CVE-2016-2140)

Affected Software/OS:
'nova' package(s) on Ubuntu 14.04.

Solution:
Please install the updated package(s).

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2015-3241
75372
http://www.securityfocus.com/bid/75372
RHSA-2015:1723
http://rhn.redhat.com/errata/RHSA-2015-1723.html
RHSA-2015:1898
http://rhn.redhat.com/errata/RHSA-2015-1898.html
https://github.com/openstack/ossa/blob/482576204dec96f580817b119e3166d71c757731/ossa/OSSA-2015-015.yaml
https://launchpad.net/bugs/1387543
https://security.openstack.org/ossa/OSSA-2015-015.html
Common Vulnerability Exposure (CVE) ID: CVE-2015-3280
76553
http://www.securityfocus.com/bid/76553
http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
https://launchpad.net/bugs/1392527
https://security.openstack.org/ossa/OSSA-2015-017.html
Common Vulnerability Exposure (CVE) ID: CVE-2015-5162
76849
http://www.securityfocus.com/bid/76849
RHSA-2016:2923
http://rhn.redhat.com/errata/RHSA-2016-2923.html
RHSA-2016:2991
http://rhn.redhat.com/errata/RHSA-2016-2991.html
RHSA-2017:0153
http://rhn.redhat.com/errata/RHSA-2017-0153.html
RHSA-2017:0156
http://rhn.redhat.com/errata/RHSA-2017-0156.html
RHSA-2017:0165
http://rhn.redhat.com/errata/RHSA-2017-0165.html
RHSA-2017:0282
http://rhn.redhat.com/errata/RHSA-2017-0282.html
[oss-security] 20161006 OSSA 2016-012] Malicious qemu-img input may exhaust resources in Cinder, Glance, Nova (CVE-2015-5162)
http://www.openwall.com/lists/oss-security/2016/10/06/8
https://launchpad.net/bugs/1449062
Common Vulnerability Exposure (CVE) ID: CVE-2015-7548
80176
http://www.securityfocus.com/bid/80176
RHSA-2016:0018
http://rhn.redhat.com/errata/RHSA-2016-0018.html
https://security.openstack.org/ossa/OSSA-2016-001.html
Common Vulnerability Exposure (CVE) ID: CVE-2015-7713
76960
http://www.securityfocus.com/bid/76960
RHSA-2015:2673
https://access.redhat.com/errata/RHSA-2015:2673
RHSA-2015:2684
http://rhn.redhat.com/errata/RHSA-2015-2684.html
https://bugs.launchpad.net/nova/+bug/1491307
https://bugs.launchpad.net/nova/+bug/1492961
https://security.openstack.org/ossa/OSSA-2015-021.html
Common Vulnerability Exposure (CVE) ID: CVE-2015-8749
BugTraq ID: 80189
http://www.securityfocus.com/bid/80189
http://www.openwall.com/lists/oss-security/2016/01/07/8
http://www.openwall.com/lists/oss-security/2016/01/07/9
Common Vulnerability Exposure (CVE) ID: CVE-2016-2140
84277
http://www.securityfocus.com/bid/84277
[oss-security] 20160308 Re: [OSSA 2016-007] Nova host data leak through resize/migration (CVE-2016-2140)
http://www.openwall.com/lists/oss-security/2016/03/08/6
https://bugs.launchpad.net/nova/+bug/1548450
https://security.openstack.org/ossa/OSSA-2016-007.html
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.