Vulnerability Name: | CVE-2013-1838 (CCN-82877) | ||||||||||||||||
Assigned: | 2013-03-14 | ||||||||||||||||
Published: | 2013-03-14 | ||||||||||||||||
Updated: | 2017-08-29 | ||||||||||||||||
Summary: | OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via a large number of calls to the addFixedIp function. Per http://www.ubuntu.com/usn/usn-1771-1/ "A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.10 Ubuntu 12.04 LTS Ubuntu 11.10" | ||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-399 | ||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-1838 Source: OSVDB Type: UNKNOWN 91303 Source: REDHAT Type: UNKNOWN RHSA-2013:0709 Source: CCN Type: SA52580 OpenStack Compute (Nova) Fixed IPs Denial of Service Vulnerability Source: SECUNIA Type: Vendor Advisory 52580 Source: SECUNIA Type: Vendor Advisory 52728 Source: UBUNTU Type: UNKNOWN USN-1771-1 Source: CCN Type: OpenStack Web site Nova Source: MLIST Type: UNKNOWN [oss-security] 20130314 [OSSA 2013-008] Nova DoS by allocating all Fixed IPs (CVE-2013-1838) Source: BID Type: UNKNOWN 58492 Source: CCN Type: BID-58492 OpenStack Nova CVE-2013-1838 Denial of Service Vulnerability Source: CONFIRM Type: UNKNOWN https://bugs.launchpad.net/nova/+bug/1125468 Source: CCN Type: Red Hat Bugzilla Bug 919648 CVE-2013-1838 Openstack Nova: DoS by allocating all Fixed IPs Source: MISC Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=919648 Source: XF Type: UNKNOWN nova-fixedips-dos(82877) Source: XF Type: UNKNOWN nova-fixedips-dos(82877) Source: MLIST Type: UNKNOWN [openstack] 20130314 [OSSA 2013-008] Nova DoS by allocating all Fixed IPs (CVE-2013-1838) Source: CONFIRM Type: UNKNOWN https://review.openstack.org/#/c/24451/ Source: CONFIRM Type: UNKNOWN https://review.openstack.org/#/c/24452/ Source: CONFIRM Type: UNKNOWN https://review.openstack.org/#/c/24453/ | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |