Lucene search

K
ubuntuUbuntuUSN-1305-1
HistoryDec 13, 2011 - 12:00 a.m.

Nova vulnerability

2011-12-1300:00:00
ubuntu.com
39

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.2

Confidence

Low

EPSS

0.005

Percentile

76.7%

Releases

  • Ubuntu 11.10

Packages

  • nova - OpenStack Compute cloud infrastructure

Details

David Black discovered that Nova did not properly perform input validation
during image registration. An attacker could exploit this by registering a
crafted image using the EC2 API or S3/RegisterImage method and overwrite
files as the nova user.

Rows per page:
1-10 of 151

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.2

Confidence

Low

EPSS

0.005

Percentile

76.7%