CVE-2013-2256

Publication date 6 August 2013

Last updated 24 July 2024


Ubuntu priority

OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor id.

Read the notes from the security team

Status

Package Ubuntu Release Status
nova 13.10 saucy
Not affected
13.04 raring
Fixed 1:2013.1.3-0ubuntu1.1
12.10 quantal
Fixed 2012.2.4-0ubuntu3.1
12.04 LTS precise
Not affected
10.04 LTS lucid Not in release

Notes


seth-arnold

See also CVE-2013-4278 when patching 12.10 and 13.04


jdstrand

Ubuntu 13.04 has fix in raring-updates flavor_access.py API extension not available on Essex (Ubuntu 12.04 LTS)

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
nova

References

Related Ubuntu Security Notices (USN)

Other references