Resource Management Errors Affecting nova package, versions <2013.1.2-2
Snyk CVSS
Attack Complexity
Low
Threat Intelligence
EPSS
0.04% (6th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIAN12-NOVA-1555148
- published 9 Jul 2013
- disclosed 9 Jul 2013
Introduced: 9 Jul 2013
CVE-2013-2096 Open this link in a new tabHow to fix?
Upgrade Debian:12
nova
to version 2013.1.2-2 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream nova
package and not the nova
package as distributed by Debian
.
See How to fix?
for Debian:12
relevant fixed versions and status.
OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by creating an image with a large virtual size that does not contain a large amount of data.
References
- https://security-tracker.debian.org/tracker/CVE-2013-2096
- http://lists.openstack.org/pipermail/openstack-announce/2013-May/000102.html
- https://review.openstack.org/#/c/28717/
- https://review.openstack.org/#/c/28901/
- https://review.openstack.org/#/c/29192/
- http://www.securityfocus.com/bid/59924
- http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-2096
- http://www.ubuntu.com/usn/USN-1831-1