Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-3517
HistoryAug 07, 2014 - 12:00 a.m.

CVE-2014-3517

2014-08-0700:00:00
ubuntu.com
ubuntu.com
9

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

0.003 Low

EPSS

Percentile

70.0%

api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x
before 2014.1.2, and Juno before Juno-2, when proxying metadata requests
through Neutron, makes it easier for remote attackers to guess instance ID
signatures via a brute-force attack that relies on timing differences in
responses to instance metadata requests.

Bugs

Notes

Author Note
jdstrand per upstream, Only setups configured to proxy metadata requests via Neutron are affected
OSVersionArchitecturePackageVersionFilename
ubuntu14.04noarchnova< 1:2014.1.2-0ubuntu1UNKNOWN

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

0.003 Low

EPSS

Percentile

70.0%