Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2013-4185

Published: 7 August 2013

Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-3 does not properly handle network source security group policy updates, which allows remote authenticated users to cause a denial of service (nova-network consumption) via a large number of server-creation operations, which triggers a large number of update requests.

Notes

AuthorNote
jdstrand
Ubuntu 13.04 has fix in raring-updates

Priority

Medium

Status

Package Release Status
nova
Launchpad, Ubuntu, Debian
upstream
Released (1:2013.2~rc2)
lucid Does not exist

precise
Released (2012.1.3+stable-20130423-e52e6912-0ubuntu1.2)
quantal
Released (2012.2.4-0ubuntu3.1)
raring
Released (1:2013.1.3-0ubuntu1.1)
saucy Not vulnerable
(1:2013.2~rc2-0ubuntu1)
Patches:
upstream: https://review.openstack.org/39541 (havana)
upstream: https://review.openstack.org/39543 (grizzly)
upstream: https://review.openstack.org/39544 (folsom)