Oval Definition:oval:org.mitre.oval:def:16948
Revision Date:2014-06-30Version:9
Title:openSUSE-SU-2013:1087-1: update for openstack-nova
Description:keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.
Family:unixClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2013-2030
Platform(s):openSUSE 12.3
Product(s):
Definition Synopsis
  • openSUSE 12.3 is installed
  • AND Packages section
  • Package python-greenlet is less than 0.4.0-3.3.1
  • OR Package python-greenlet-debuginfo is less than 0.4.0-3.3.1
  • OR Package python-greenlet-debugsource is less than 0.4.0-3.3.1
  • OR Package openstack-nova is less than 2012.2.4+git.1363297910.9561484-2.10.1
  • OR Package openstack-nova-api is less than 2012.2.4+git.1363297910.9561484-2.10.1
  • OR Package openstack-nova-cert is less than 2012.2.4+git.1363297910.9561484-2.10.1
  • OR Package openstack-nova-compute is less than 2012.2.4+git.1363297910.9561484-2.10.1
  • OR Package openstack-nova-doc is less than 2012.2.4+git.1363297910.9561484-2.10.1
  • OR Package openstack-nova-network is less than 2012.2.4+git.1363297910.9561484-2.10.1
  • OR Package openstack-nova-novncproxy is less than 2012.2.4+git.1363297910.9561484-2.10.1
  • OR Package openstack-nova-objectstore is less than 2012.2.4+git.1363297910.9561484-2.10.1
  • OR Package openstack-nova-scheduler is less than 2012.2.4+git.1363297910.9561484-2.10.1
  • OR Package openstack-nova-test is less than 2012.2.4+git.1363297910.9561484-2.10.1
  • OR Package openstack-nova-vncproxy is less than 2012.2.4+git.1363297910.9561484-2.10.1
  • OR Package openstack-nova-volume is less than 2012.2.4+git.1363297910.9561484-2.10.1
  • OR Package python-greenlet-devel is less than 0.4.0-3.3.1
  • OR Package python-nova is less than 2012.2.4+git.1363297910.9561484-2.10.1
  • BACK